Vulnerabilities > Cyberpowersystems

DATE CVE VULNERABILITY TITLE RISK
2019-07-10 CVE-2019-13071 Cross-Site Request Forgery (CSRF) vulnerability in Cyberpowersystems Powerpanel 3.4.0
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application.
network
low complexity
cyberpowersystems CWE-352
8.8
2019-07-09 CVE-2019-13070 Cross-site Scripting vulnerability in Cyberpowersystems Powerpanel 3.4.0
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form.
network
low complexity
cyberpowersystems CWE-79
5.4