VYPR
Vendor

Sims

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2022-34549HigJul 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.

  • CVE-2022-34551MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Sims v1.0 was discovered to allow path traversal when downloading attachments.

  • CVE-2022-34550MedJul 27, 2022
    risk 0.35cvss 5.4epss 0.01

    Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.