Vulnerabilities > XM Online

DATE CVE VULNERABILITY TITLE RISK
2019-08-26 CVE-2019-15558 SQL Injection vulnerability in Xm-Online Xm^Online 2 - Common Utils and Endpoints 0.2.1
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
network
low complexity
xm-online CWE-89
critical
9.8
2019-08-26 CVE-2019-15557 SQL Injection vulnerability in Xm-Online Xm^Online 2 User Account and Authentication Server 1.0.0
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
network
low complexity
xm-online CWE-89
critical
9.8