VYPR

Open Audit

by Open Audit

Source repositories

CVEs (13)

  • CVE-2020-11942CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

  • CVE-2018-8979HigMar 25, 2018
    risk 0.60cvss 8.8epss 0.01

    Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

  • CVE-2020-11943HigApr 29, 2020
    risk 0.59cvss 8.8epss 0.24

    An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

  • CVE-2020-12078HigApr 28, 2020
    risk 0.58cvss 8.8epss 0.10

    An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip…

  • CVE-2020-11941HigApr 27, 2020
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

  • CVE-2019-16293HigSep 13, 2019
    risk 0.50cvss 8.8epss 0.02

    The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.

  • CVE-2018-9137MedApr 19, 2018
    risk 0.47cvss 6.8epss 0.03

    Open-AudIT before 2.2 has CSV Injection.

  • CVE-2018-8937MedMar 26, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.

  • CVE-2021-3130MedJan 20, 2021
    risk 0.38cvss 5.9epss 0.01

    Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the…

  • CVE-2018-8903MedMar 22, 2018
    risk 0.38cvss 5.4epss 0.02

    Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.

  • CVE-2018-8978MedMar 25, 2018
    risk 0.35cvss 5.4epss 0.01

    Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.

  • CVE-2018-11124MedJul 6, 2018
    risk 0.31cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.

  • CVE-2018-9155MedApr 12, 2018
    risk 0.31cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section…