Vulnerabilities > Sapplica

DATE CVE VULNERABILITY TITLE RISK
2024-03-21 CVE-2024-29870 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29871 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29872 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29873 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29874 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29875 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29876 Unspecified vulnerability in Sapplica Sentrifugo 3.2
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter.
network
low complexity
sapplica
critical
9.8
2024-03-21 CVE-2024-29877 Unspecified vulnerability in Sapplica Sentrifugo 3.2
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter.
network
low complexity
sapplica
6.1
2024-03-21 CVE-2024-29878 Unspecified vulnerability in Sapplica Sentrifugo 3.2
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter.
network
low complexity
sapplica
6.1
2024-03-21 CVE-2024-29879 Unspecified vulnerability in Sapplica Sentrifugo 3.2
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.
network
low complexity
sapplica
6.1