VYPR
Vendor

Sergestec

Products
2
CVEs
4
Across products
5
Status
Private

Products

2

Recent CVEs

4
  • CVE-2025-41018CriOct 16, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.

  • CVE-2025-41019CriOct 16, 2025
    risk 0.60cvss epss 0.00

    SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.

  • CVE-2025-41020HigOct 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.

  • CVE-2025-41021MedOct 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=product_update'. This vulnerability could allow a remote user…