Vulnerabilities > Saysis

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2023-1198 SQL Injection vulnerability in Saysis Starcities 1.1/1.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection.This issue affects Starcities: through 1.3.
network
low complexity
saysis CWE-89
critical
9.8
2023-03-10 CVE-2023-1246 Files or Directories Accessible to External Parties vulnerability in Saysis Starcities 1.1/1.3
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations.This issue affects Starcities: through 1.3.
network
low complexity
saysis CWE-552
7.5
2023-03-06 CVE-2022-2178 Cross-site Scripting vulnerability in Saysis Starcities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saysis Computer Starcities allows Cross-Site Scripting (XSS).This issue affects Starcities: before 1.1.
network
low complexity
saysis CWE-79
6.1