VYPR
Vendor

Opengnsys

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2024-3704CriApr 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login page to bypass it or even retrieve all the information stored in the database.

  • CVE-2024-3705HigApr 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request to the endpoint '/opengnsys/images/M_Icons.php' modifying the file extension, due to lack of file extension verification, resulting…

  • CVE-2024-3706MedApr 12, 2024
    risk 0.38cvss 5.9epss 0.01

    Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (controlaccess.php-LAST) where database credentials are stored.

  • CVE-2024-3707MedApr 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.