Vulnerabilities > Ahsay

DATE CVE VULNERABILITY TITLE RISK
2022-09-21 CVE-2022-37027 Argument Injection or Modification vulnerability in Ahsay Cloud Backup Suite 9.1.4.0
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options.
network
low complexity
ahsay CWE-88
7.2
2020-01-06 CVE-2020-5846 Unrestricted Upload of File with Dangerous Type vulnerability in Ahsay Cloud Backup Suite 8.3.0.30
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body.
network
low complexity
ahsay CWE-434
4.0
2019-07-26 CVE-2019-10267 Unrestricted Upload of File with Dangerous Type vulnerability in Ahsay Cloud Backup Suite
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50.
network
low complexity
ahsay CWE-434
critical
9.0
2019-07-26 CVE-2019-10266 XXE vulnerability in Ahsay Cloud Backup Suite
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50.
network
low complexity
ahsay CWE-611
7.8
2019-07-26 CVE-2019-10265 Path Traversal vulnerability in Ahsay Cloud Backup Suite
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50.
network
low complexity
ahsay CWE-22
7.8
2019-07-26 CVE-2019-10264 XXE vulnerability in Ahsay Cloud Backup Suite
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50.
network
low complexity
ahsay CWE-611
6.5
2019-07-26 CVE-2019-10263 Cross-site Scripting vulnerability in Ahsay Cloud Backup Suite
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50.
network
ahsay CWE-79
4.3