Vulnerabilities > Bpcbt > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-09 CVE-2022-38613 Path Traversal vulnerability in Bpcbt Smartvista Cardgen 3.28.0
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
network
low complexity
bpcbt CWE-22
6.5
2022-08-19 CVE-2022-35554 Cross-site Scripting vulnerability in Bpcbt Smartvista 2/2.2.22/3.28.0
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.
network
low complexity
bpcbt CWE-79
6.1