Vulnerabilities > Rental Module Project

DATE CVE VULNERABILITY TITLE RISK
2023-05-20 CVE-2023-2712 Unrestricted Upload of File with Dangerous Type vulnerability in Rental Module Project Rental Module
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
network
low complexity
rental-module-project CWE-434
critical
9.8
2023-05-20 CVE-2023-2713 Authorization Bypass Through User-Controlled Key vulnerability in Rental Module Project Rental Module
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental Module: before 23.05.15.
network
low complexity
rental-module-project CWE-639
critical
9.8