VYPR

Provisioning Suite

by Kurmi

CVEs (5)

  • CVE-2024-54450CriDec 27, 2024
    risk 0.61cvss 9.4epss 0.00

    An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from.…

  • CVE-2024-54453HigDec 27, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder,…

  • CVE-2024-54454MedDec 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a…

  • CVE-2024-54452MedDec 27, 2024
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended…

  • CVE-2024-54451MedDec 27, 2024
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers (authenticated as system administrators) to inject arbitrary web script or…