VYPR

AdPortal

by AdPortal

CVEs (3)

  • CVE-2024-50659Jan 7, 2025
    risk 0.00cvss epss 0.00

    Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.

  • CVE-2024-50660Jan 7, 2025
    risk 0.00cvss epss 0.01

    File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

  • CVE-2024-50658Jan 7, 2025
    risk 0.00cvss epss 0.03

    Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file