Vulnerabilities > Itpison

DATE CVE VULNERABILITY TITLE RISK
2023-12-15 CVE-2023-48372 SQL Injection vulnerability in Itpison Omicard EDM 6.0.1.5
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input.
network
low complexity
itpison CWE-89
critical
9.8
2023-12-15 CVE-2023-48373 Path Traversal vulnerability in Itpison Omicard EDM 6.0.1.5
ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function.
network
low complexity
itpison CWE-22
7.5
2023-12-15 CVE-2023-48371 Unrestricted Upload of File with Dangerous Type vulnerability in Itpison Omicard EDM 6.0.1.5
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type.
network
low complexity
itpison CWE-434
critical
9.8
2023-06-16 CVE-2023-32753 Unrestricted Upload of File with Dangerous Type vulnerability in Itpison Omicard EDM
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type.
network
low complexity
itpison CWE-434
critical
9.8
2023-06-02 CVE-2023-28700 Unrestricted Upload of File with Dangerous Type vulnerability in Itpison Omicard EDM
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type.
low complexity
itpison CWE-434
6.8