Vulnerabilities > H MDM

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-47312 Cleartext Storage of Sensitive Information vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.
network
low complexity
h-mdm CWE-312
6.5
2023-11-22 CVE-2023-47313 Path Traversal vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal.
network
low complexity
h-mdm CWE-22
5.4
2023-11-22 CVE-2023-47314 Cross-site Scripting vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to cross-site scripting (XSS).
network
low complexity
h-mdm CWE-79
5.4
2023-11-22 CVE-2023-47315 Use of Hard-coded Credentials vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret.
network
low complexity
h-mdm CWE-798
8.8
2023-11-22 CVE-2023-47316 Authorization Bypass Through User-Controlled Key vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control.
network
low complexity
h-mdm CWE-639
5.4