VYPR
Vendor

Western Bridge

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2018-8057CriMar 11, 2018
    risk 0.69cvss 9.8epss 0.23

    A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.

  • CVE-2018-7746HigMar 7, 2018
    risk 0.60cvss 8.8epss 0.03

    An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, stored XSS is triggered during a later /index.php?/manage/channel request by an admin.

  • CVE-2018-7720HigMar 7, 2018
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in account creation.

  • CVE-2018-8056HigMar 11, 2018
    risk 0.53cvss 7.5epss 0.13

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.

  • CVE-2018-7745HigMar 7, 2018
    risk 0.53cvss 7.5epss 0.13

    An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo requests, resulting in account creation.

  • CVE-2018-8770MedMar 18, 2018
    risk 0.42cvss 5.3epss 0.61

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php,…

  • CVE-2019-10276Mar 29, 2019
    risk 0.00cvss epss 0.02

    Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.