VYPR
Vendor

Synchroweb

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2025-11189HigOct 10, 2025
    risk 0.47cvss 7.3epss 0.00

    The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

  • CVE-2025-11188HigOct 10, 2025
    risk 0.47cvss 7.3epss 0.00

    The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.

  • CVE-2025-11190MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

  • CVE-2013-2690Mar 28, 2013
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.