Vulnerabilities > Vembu > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-02-23 CVE-2014-10079 Information Exposure vulnerability in Vembu Storegrid 4.4
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
network
low complexity
vembu CWE-200
5.3
2019-02-23 CVE-2014-10078 Cross-site Scripting vulnerability in Vembu Storegrid 4.4
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
network
low complexity
vembu CWE-79
6.1