This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Uniguest First view 2023-04-19
Product Tripleplay Last view 2023-04-19
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:uniguest:tripleplay:3.4.0:*:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
6.1 2023-04-19 CVE-2023-26599

XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted link.

8.8 2023-04-19 CVE-2023-25760

Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload

5.4 2023-04-19 CVE-2023-25759

OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload.

CWE : Common Weakness Enumeration

%idName
33% (1) CWE-522 Insufficiently Protected Credentials
33% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
33% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...