Open Audit
Products
2- 13 CVEs
- 5 CVEs
Recent CVEs
14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11942 | Cri | 0.64 | 9.8 | 0.01 | Apr 29, 2020 | An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections. | ||
| CVE-2018-8979 | Hig | 0.60 | 8.8 | 0.01 | Mar 25, 2018 | Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI. | ||
| CVE-2020-11943 | Hig | 0.59 | 8.8 | 0.24 | Apr 29, 2020 | An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload. | ||
| CVE-2020-12078 | Hig | 0.58 | 8.8 | 0.10 | Apr 28, 2020 | An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip… | ||
| CVE-2020-11941 | Hig | 0.58 | 8.8 | 0.05 | Apr 27, 2020 | An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery. | ||
| CVE-2019-16293 | Hig | 0.50 | 8.8 | 0.02 | Sep 13, 2019 | The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. | ||
| CVE-2018-9137 | Med | 0.47 | 6.8 | 0.03 | Apr 19, 2018 | Open-AudIT before 2.2 has CSV Injection. | ||
| CVE-2018-8937 | Med | 0.40 | 6.1 | 0.01 | Mar 26, 2018 | An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code. | ||
| CVE-2021-3130 | Med | 0.38 | 5.9 | 0.01 | Jan 20, 2021 | Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the… | ||
| CVE-2018-8903 | Med | 0.38 | 5.4 | 0.02 | Mar 22, 2018 | Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen. | ||
| CVE-2018-16607 | Med | 0.35 | 5.4 | 0.01 | Sep 19, 2018 | Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field. | ||
| CVE-2018-8978 | Med | 0.35 | 5.4 | 0.01 | Mar 25, 2018 | Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI. | ||
| CVE-2018-11124 | Med | 0.31 | 5.4 | 0.02 | Jul 6, 2018 | Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute. | ||
| CVE-2018-9155 | Med | 0.31 | 5.4 | 0.01 | Apr 12, 2018 | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section… |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
- risk 0.60cvss 8.8epss 0.01
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
- risk 0.59cvss 8.8epss 0.24
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
- risk 0.58cvss 8.8epss 0.10
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip…
- risk 0.58cvss 8.8epss 0.05
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
- risk 0.50cvss 8.8epss 0.02
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
- risk 0.47cvss 6.8epss 0.03
Open-AudIT before 2.2 has CSV Injection.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.
- risk 0.38cvss 5.9epss 0.01
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the…
- risk 0.38cvss 5.4epss 0.02
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
- risk 0.35cvss 5.4epss 0.01
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
- risk 0.31cvss 5.4epss 0.02
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
- risk 0.31cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section…