Vulnerabilities > Ozeki > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-09-22 CVE-2020-14031 Unspecified vulnerability in Ozeki NG SMS Gateway
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6.
network
low complexity
ozeki
critical
9.0
2020-09-22 CVE-2020-14028 Path Traversal vulnerability in Ozeki NG SMS Gateway
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6.
network
low complexity
ozeki CWE-22
critical
9.0
2020-09-22 CVE-2020-14026 Improper Neutralization of Formula Elements in a CSV File vulnerability in Ozeki NG SMS Gateway
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
network
ozeki CWE-1236
critical
9.3
2020-09-22 CVE-2020-14022 Unrestricted Upload of File with Dangerous Type vulnerability in Ozeki NG SMS Gateway
Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file.
network
low complexity
ozeki CWE-434
critical
9.0