Vulnerabilities > Codekop

DATE CVE VULNERABILITY TITLE RISK
2023-06-30 CVE-2023-36347 Missing Authentication for Critical Function vulnerability in Codekop 2.0
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
network
low complexity
codekop CWE-306
7.5
2023-06-23 CVE-2023-36345 Cross-site Scripting vulnerability in Codekop 2.0
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
network
low complexity
codekop CWE-79
8.8
2023-06-23 CVE-2023-36346 Cross-site Scripting vulnerability in Codekop 2.0
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
network
low complexity
codekop CWE-79
6.1
2023-06-23 CVE-2023-36348 Missing Authorization vulnerability in Codekop 2.0
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
network
low complexity
codekop CWE-862
8.8