Vendor
Connx
Products
2
CVEs
4
Across products
4
Status
Private
Products
2- 2 CVEs
- 2 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-4043 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2018 | SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx. | ||
| CVE-2021-40650 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2022 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set. | ||
| CVE-2021-40649 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2022 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. | ||
| CVE-2024-7269 | Med | 0.35 | 5.4 | 0.00 | Aug 28, 2024 | Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we… |
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx.
- risk 0.42cvss 6.5epss 0.01
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
- risk 0.42cvss 6.5epss 0.01
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
- risk 0.35cvss 5.4epss 0.00
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we…