Vulnerabilities > Smeup

DATE CVE VULNERABILITY TITLE RISK
2023-02-27 CVE-2023-26758 Path Traversal vulnerability in Smeup ERP Tokyov6R1M220406
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.
network
low complexity
smeup CWE-22
7.5
2023-02-27 CVE-2023-26759 OS Command Injection vulnerability in Smeup ERP Tokyov6R1M220406
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.
network
low complexity
smeup CWE-78
8.8
2023-02-27 CVE-2023-26760 Cleartext Storage of Sensitive Information vulnerability in Smeup ERP Tokyov6R1M220406
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint.
network
low complexity
smeup CWE-312
7.5
2023-02-27 CVE-2023-26762 Unrestricted Upload of File with Dangerous Type vulnerability in Smeup ERP Tokyov6R1M220406
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
smeup CWE-434
8.8