Vulnerabilities > Handysoft > Groupware

DATE CVE VULNERABILITY TITLE RISK
2022-05-19 CVE-2021-26630 Improper Input Validation vulnerability in Handysoft Groupware
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files.
network
low complexity
handysoft CWE-20
7.5
2020-04-29 CVE-2020-7804 OS Command Injection vulnerability in Handysoft Groupware 1.7.3.1
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.
network
low complexity
handysoft CWE-78
6.5