Vulnerabilities > Ieasytec > Itrackeasy

DATE CVE VULNERABILITY TITLE RISK
2018-07-13 CVE-2016-6545 Session Fixation vulnerability in Ieasytec Itrackeasy
Session cookies are not used for maintaining valid sessions in iTrack Easy.
network
low complexity
ieasytec CWE-384
5.0
2018-07-13 CVE-2016-6542 Improper Input Validation vulnerability in Ieasytec Itrackeasy
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device.
network
ieasytec CWE-20
4.3