Skip to main content

Vendor archive

homeautomation_project CVEs

Beta · best-effort

5 CVEs tagged to vendor homeautomation_project1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-22001

Published Apr 27, 2021

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address valu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-21998

Published Apr 27, 2021

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21989

Published Apr 27, 2021

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any v…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-21987

Published Apr 27, 2021

HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1