Vulnerabilities > Matera > Banco > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-03 CVE-2018-14928 Information Exposure vulnerability in Matera Banco 1.0.0
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
network
low complexity
matera CWE-200
7.5
2018-08-03 CVE-2018-14926 Cross-Site Request Forgery (CSRF) vulnerability in Matera Banco 1.0.0
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
network
low complexity
matera CWE-352
8.8