Vulnerabilities > Archerirm

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-48641 Authorization Bypass Through User-Controlled Key vulnerability in Archerirm Archer
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability.
network
low complexity
archerirm CWE-639
8.8
2023-12-12 CVE-2023-48642 Cross-site Scripting vulnerability in Archerirm Archer
Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability.
network
low complexity
archerirm CWE-79
5.4
2023-10-17 CVE-2023-45357 Exposure of Resource to Wrong Sphere vulnerability in Archerirm Archer
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability.
network
low complexity
archerirm CWE-668
6.5
2023-10-17 CVE-2023-45358 Cross-site Scripting vulnerability in Archerirm Archer
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability.
network
low complexity
archerirm CWE-79
5.4
2023-07-14 CVE-2023-32759 Exposure of Resource to Wrong Sphere vulnerability in Archerirm Archer 6.10.0.3/6.3.0.0/6.9.3.4
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
network
low complexity
archerirm CWE-668
6.5
2023-07-14 CVE-2023-32760 Exposure of Resource to Wrong Sphere vulnerability in Archerirm Archer 6.10.0.3/6.3.0.0/6.9.3.4
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
network
low complexity
archerirm CWE-668
6.5
2023-07-14 CVE-2023-32761 Cross-Site Request Forgery (CSRF) vulnerability in Archerirm Archer 6.10.0.3/6.3.0.0/6.9.3.4
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
network
low complexity
archerirm CWE-352
8.0
2023-07-14 CVE-2023-37223 Cross-site Scripting vulnerability in Archerirm Archer
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
network
low complexity
archerirm CWE-79
5.4
2023-07-14 CVE-2023-37224 Information Exposure Through Log Files vulnerability in Archerirm Archer
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
local
low complexity
archerirm CWE-532
5.5
2023-05-01 CVE-2023-30639 Cross-site Scripting vulnerability in Archerirm Archer 6.10.0.3/6.9.3.4
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability.
network
low complexity
archerirm CWE-79
5.4