Vendor
Granding
Products
2
CVEs
4
Across products
4
Status
Private
Products
2- 2 CVEs
- 2 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-5381 | Cri | 0.67 | 9.8 | 0.07 | Jan 13, 2020 | Grand MA 300 allows a brute-force attack on the PIN. | ||
| CVE-2014-5380 | Hig | 0.52 | 7.5 | 0.04 | Jan 13, 2020 | Grand MA 300 allows retrieval of the access PIN from sniffed data. | ||
| CVE-2023-45393 | Med | 0.42 | 6.5 | 0.00 | Oct 13, 2023 | An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie. | ||
| CVE-2023-45391 | Med | 0.31 | 4.8 | 0.00 | Oct 13, 2023 | A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter. |
- risk 0.67cvss 9.8epss 0.07
Grand MA 300 allows a brute-force attack on the PIN.
- risk 0.52cvss 7.5epss 0.04
Grand MA 300 allows retrieval of the access PIN from sniffed data.
- risk 0.42cvss 6.5epss 0.00
An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.
- risk 0.31cvss 4.8epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.