Vulnerabilities > Beims
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-01-15 | CVE-2018-5329 | Cross-Site Request Forgery (CSRF) vulnerability in Beims Contractorweb.Net 5.18.0.0 ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. | 8.8 |
2018-01-15 | CVE-2018-5328 | Improper Authentication vulnerability in Beims Contractorweb.Net 5.18.0.0 ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details. | 9.8 |