Vulnerabilities > White Shark Systems Project

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2020-20469 SQL Injection vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability.
network
low complexity
white-shark-systems-project CWE-89
7.5
2021-06-21 CVE-2020-20470 Information Exposure Through an Error Message vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
network
low complexity
white-shark-systems-project CWE-209
5.3
2021-06-21 CVE-2020-20471 Incorrect Authorization vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.
network
low complexity
white-shark-systems-project CWE-863
8.8
2021-06-21 CVE-2020-20472 Missing Authentication for Critical Function vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability.
network
low complexity
white-shark-systems-project CWE-306
5.3
2021-06-21 CVE-2020-20473 SQL Injection vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability.
network
low complexity
white-shark-systems-project CWE-89
7.5
2021-06-21 CVE-2020-20474 SQL Injection vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability.
network
low complexity
white-shark-systems-project CWE-89
7.5
2021-06-21 CVE-2020-20466 Incorrect Authorization vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
network
low complexity
white-shark-systems-project CWE-863
critical
9.8
2021-06-21 CVE-2020-20467 Unspecified vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.
network
low complexity
white-shark-systems-project
6.5
2021-06-21 CVE-2020-20468 Cross-Site Request Forgery (CSRF) vulnerability in White Shark Systems Project White Shark Systems 1.3.2
White Shark System (WSS) 1.3.2 is vulnerable to CSRF.
network
low complexity
white-shark-systems-project CWE-352
6.5