VYPR
Vendor

Xpand It

Products
3
CVEs
6
Across products
7
Status
Private

Products

3

Recent CVEs

6
  • CVE-2023-27168CriJan 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

  • CVE-2023-27172CriDec 20, 2023
    risk 0.59cvss 9.1epss 0.01

    Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.

  • CVE-2023-27170HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

  • CVE-2023-27169MedSep 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

  • CVE-2019-19679MedDec 9, 2019
    risk 0.35cvss 5.4epss 0.01

    In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.

  • CVE-2019-19678MedDec 9, 2019
    risk 0.35cvss 5.4epss 0.01

    In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.