VYPR
Vendor

Ortussolutions

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2020-15929CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.05

    In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

  • CVE-2020-15928MedNov 24, 2020
    risk 0.35cvss 5.3epss 0.02

    In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.

  • CVE-2021-4430LowNov 6, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is…