Vulnerabilities > Landray

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2024-11239 Path Traversal vulnerability in Landray EKP 12.0.9.R.20160325
A vulnerability has been found in Landray EKP up to 16.0 and classified as critical.
network
low complexity
landray CWE-22
4.3
2024-11-15 CVE-2024-11238 Path Traversal vulnerability in Landray EKP 12.0.9.R.20160325
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0.
network
low complexity
landray CWE-22
5.3
2022-08-02 CVE-2022-34924 Cleartext Storage of Sensitive Information vulnerability in Landray Office Automation
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
network
low complexity
landray CWE-312
7.5
2021-07-23 CVE-2021-3159 Cross-site Scripting vulnerability in Landray EKP 12.0.9.R.20160325
A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.
network
low complexity
landray CWE-79
5.4