Summary
Detail | |||
---|---|---|---|
Vendor | Uniguest | First view | 2023-04-19 |
Product | Tripleplay | Last view | 2023-04-19 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:uniguest:tripleplay:3.4.0:*:*:*:*:*:*:* | 3 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.1 | 2023-04-19 | CVE-2023-26599 | XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted link. |
8.8 | 2023-04-19 | CVE-2023-25760 | Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload |
5.4 | 2023-04-19 | CVE-2023-25759 | OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
33% (1) | CWE-522 | Insufficiently Protected Credentials |
33% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
33% (1) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |