VYPR
Vendor

ORDAT

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2024-34334HigSep 12, 2024
    risk 0.49cvss 7.5epss 0.00

    ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.

  • CVE-2024-34335MedSep 12, 2024
    risk 0.40cvss 6.1epss 0.00

    ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.

  • CVE-2024-34336MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.