VYPR
Vendor

Zucchetti

Products
13
CVEs
25
Across products
28
Status
Private

Products

13

Recent CVEs

25
View all 25 CVEs →
  • CVE-2021-42369CriOct 14, 2021
    risk 0.64cvss 9.9epss 0.01

    Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

  • CVE-2023-42228HigJan 13, 2025
    risk 0.57cvss 8.8epss 0.00

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.

  • CVE-2019-18206HigOct 30, 2019
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.

  • CVE-2019-18204HigOct 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

  • CVE-2023-42231HigJan 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.

  • CVE-2024-51321HigMar 11, 2025
    risk 0.49cvss 7.6epss 0.00

    In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.

  • CVE-2023-42232HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

  • CVE-2023-42227HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.

  • CVE-2023-42226HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.

  • CVE-2023-42225HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

  • CVE-2019-10257HigJun 19, 2019
    risk 0.49cvss 7.5epss 0.02

    Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash notation) to access files or directories that are elsewhere on the system. Through this vulnerability it is possible to read the…

  • CVE-2024-51319HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.

  • CVE-2023-42229MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.01

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.

  • CVE-2026-30695MedMar 18, 2026
    risk 0.40cvss 6.1epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the…

  • CVE-2025-61431MedNov 4, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted…

  • CVE-2025-52180MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint.

  • CVE-2025-52179MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahrw/jsp/gsfr_feditorHTML.jsp endpoint.

  • CVE-2023-42233MedJan 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

  • CVE-2023-42230MedJan 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

  • CVE-2019-18205MedOct 30, 2019
    risk 0.40cvss 6.1epss 0.01

    Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.