VYPR

Performa 365

by InfoDom

CVEs (2)

  • CVE-2024-46624HigDec 3, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.

  • CVE-2024-46625HigDec 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.