Vulnerabilities > Ebankit

DATE CVE VULNERABILITY TITLE RISK
2023-05-28 CVE-2023-33291 Incorrect Default Permissions vulnerability in Ebankit 6
In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation.
network
high complexity
ebankit CWE-276
7.4
2023-04-28 CVE-2023-30454 Cross-site Scripting vulnerability in Ebankit 6/6.0
An issue was discovered in ebankIT before 7.
network
low complexity
ebankit CWE-79
6.1
2023-04-28 CVE-2023-30455 Unspecified vulnerability in Ebankit 6/6.0
An issue was discovered in ebankIT before 7.
network
low complexity
ebankit
7.5