Vulnerabilities > Shilpisoft

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-47652 Unspecified vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number.
network
high complexity
shilpisoft
8.1
2024-10-04 CVE-2024-47653 Unspecified vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints.
network
low complexity
shilpisoft
6.5
2024-10-04 CVE-2024-47654 Unspecified vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint.
network
low complexity
shilpisoft
7.5
2024-10-04 CVE-2024-47655 Unrestricted Upload of File with Dangerous Type vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension.
network
low complexity
shilpisoft CWE-434
8.8
2024-10-04 CVE-2024-47656 Improper Restriction of Excessive Authentication Attempts vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login.
network
low complexity
shilpisoft CWE-307
critical
9.8
2024-10-04 CVE-2024-47657 Authorization Bypass Through User-Controlled Key vulnerability in Shilpisoft NET Back Office
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints.
network
low complexity
shilpisoft CWE-639
6.5