Vulnerabilities > Gruparge

DATE CVE VULNERABILITY TITLE RISK
2023-02-12 CVE-2022-45085 Server-Side Request Forgery (SSRF) vulnerability in Gruparge Smartpower web
Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery.This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-918
6.5
2023-02-12 CVE-2022-45086 Cross-site Scripting vulnerability in Gruparge Smartpower web
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-79
5.4
2023-02-12 CVE-2022-45087 Cross-site Scripting vulnerability in Gruparge Smartpower web
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-79
6.1
2023-02-12 CVE-2022-45088 Improper Input Validation vulnerability in Gruparge Smartpower web
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion.This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-20
critical
9.8
2023-02-12 CVE-2022-45089 SQL Injection vulnerability in Gruparge Smartpower web
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-89
8.8
2023-02-12 CVE-2022-45090 SQL Injection vulnerability in Gruparge Smartpower web
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-89
8.8
2023-02-12 CVE-2022-45091 Cross-site Scripting vulnerability in Gruparge Smartpower web
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS).This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-79
5.4
2023-02-12 CVE-2022-4557 SQL Injection vulnerability in Gruparge Smartpower
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01.
network
low complexity
gruparge CWE-89
critical
9.8