Vulnerabilities > Echa Europa

DATE CVE VULNERABILITY TITLE RISK
2024-01-21 CVE-2024-0770 Incorrect Default Permissions vulnerability in Echa.Europa Iuclid 7.10.3
A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows.
local
low complexity
echa-europa CWE-276
7.1
2023-05-02 CVE-2023-26089 Use of Hard-coded Credentials vulnerability in Echa.Europa Iuclid
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing.
network
low complexity
echa-europa CWE-798
critical
9.8
2023-05-02 CVE-2023-26546 Unspecified vulnerability in Echa.Europa Iuclid
European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file.
network
low complexity
echa-europa
8.8