Skip to main content

Vendor archive

bigprof CVEs

Beta · best-effort

22 CVEs tagged to vendor bigprof1 Critical, 2 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2023-6435

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6434

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6433

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6432

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6431

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6430

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6429

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6428

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6427

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6426

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6425

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6424

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6423

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6422

Published Nov 30, 2023

A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35675

Published Sep 29, 2022

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35674

Published Sep 29, 2022

BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27839

Published Mar 3, 2021

A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21260

Published Jan 22, 2021

Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35677

Published Dec 24, 2020

BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resul…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35676

Published Dec 24, 2020

BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can inp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6583

Published Jan 8, 2020

BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie f…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18587

Published Oct 23, 2018

BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1