VYPR
Vendor

Folio Org

Products
4
CVEs
4
Across products
4
Status
Private

Products

4

Recent CVEs

4
  • CVE-2024-23687CriJan 19, 2024
    risk 0.52cvss 9.1epss 0.01

    Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines.

  • CVE-2022-4963MedMar 21, 2024
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function dropSchema of the file tenant/src/main/java/org/folio/spring/tenant/hibernate/HibernateSchemaService.java of the component Schema Name…

  • CVE-2024-23685MedJan 19, 2024
    risk 0.27cvss 5.3epss 0.01

    Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.

  • CVE-2019-15534CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.