Vulnerabilities > Globalnorthstar

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2021-29393 OS Command Injection vulnerability in Globalnorthstar Northstar Club Management 6.3
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
network
low complexity
globalnorthstar CWE-78
critical
10.0
2022-02-04 CVE-2021-29394 Incorrect Authorization vulnerability in Globalnorthstar Northstar Club Management 6.3
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.
network
low complexity
globalnorthstar CWE-863
4.0
2022-02-04 CVE-2021-29395 Path Traversal vulnerability in Globalnorthstar Northstar Club Management 6.3
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
network
low complexity
globalnorthstar CWE-22
5.0
2022-02-04 CVE-2021-29396 Incorrect Permission Assignment for Critical Resource vulnerability in Globalnorthstar Northstar Club Management 6.3
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
network
low complexity
globalnorthstar CWE-732
7.5
2022-02-04 CVE-2021-29397 Cleartext Transmission of Sensitive Information vulnerability in Globalnorthstar Northstar Club Management 6.3
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.
network
low complexity
globalnorthstar CWE-319
5.0
2022-02-04 CVE-2021-29398 Path Traversal vulnerability in Globalnorthstar Northstar Club Management 6.3
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
network
low complexity
globalnorthstar CWE-22
5.0