Vulnerabilities > Saphira

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2023-4661 SQL Injection vulnerability in Saphira Connect
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection.This issue affects Saphira Connect: before 9.
network
low complexity
saphira CWE-89
critical
9.8
2023-09-15 CVE-2023-4662 Improper Privilege Management vulnerability in Saphira Connect
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion.This issue affects Saphira Connect: before 9.
network
low complexity
saphira CWE-269
critical
9.8
2023-09-15 CVE-2023-4663 Cross-site Scripting vulnerability in Saphira Connect
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS.This issue affects Saphira Connect: before 9.
network
low complexity
saphira CWE-79
6.1
2023-09-15 CVE-2023-4664 Incorrect Default Permissions vulnerability in Saphira Connect
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.
network
low complexity
saphira CWE-276
8.8
2023-09-15 CVE-2023-4665 Incorrect Permission Assignment for Critical Resource vulnerability in Saphira Connect
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.
network
low complexity
saphira CWE-732
8.8