Vulnerabilities > Handysoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-08-07 CVE-2020-7810 Improper Validation of Integrity Check Value vulnerability in Handysoft Hslogin2.Dll 6.7.8.4/7.3.4
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method.
network
low complexity
handysoft CWE-354
8.8
2020-04-29 CVE-2020-7804 OS Command Injection vulnerability in Handysoft Groupware 1.7.3.1
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.
network
low complexity
handysoft CWE-78
7.2