VYPR

BEIMS ContractorWeb

by ZUUSE

CVEs (3)

  • CVE-2017-17721CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.07

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

  • CVE-2018-5328Jan 15, 2018
    risk 0.00cvss epss 0.00

    ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details.

  • CVE-2018-5329Jan 15, 2018
    risk 0.00cvss epss 0.00

    ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative…