Vulnerabilities > Steelcase
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-02-15 | CVE-2018-7057 | Cross-site Scripting vulnerability in Steelcase Roomwizard Firmware RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter. | 6.1 |
2018-02-15 | CVE-2018-7056 | Information Exposure vulnerability in Steelcase Roomwizard Firmware RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action. | 5.3 |
2018-02-15 | CVE-2018-7055 | Server-Side Request Forgery (SSRF) vulnerability in Steelcase Roomwizard Firmware GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter. | 7.5 |