Vulnerabilities > Ebankit
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-28 | CVE-2023-33291 | Incorrect Default Permissions vulnerability in Ebankit 6 In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. | 7.4 |
2023-04-28 | CVE-2023-30454 | Cross-site Scripting vulnerability in Ebankit 6/6.0 An issue was discovered in ebankIT before 7. | 6.1 |
2023-04-28 | CVE-2023-30455 | Unspecified vulnerability in Ebankit 6/6.0 An issue was discovered in ebankIT before 7. | 7.5 |