VYPR

Provisioning Suite

by Kurmi

CVEs (3)

  • CVE-2024-54450CriDec 27, 2024
    risk 0.61cvss 9.4epss 0.01

    An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from.…

  • CVE-2024-54453HigDec 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder,…

  • CVE-2024-54452MedDec 27, 2024
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended…