Skip to main content

Vendor/product archive

italtel / embrace CVEs

Beta · best-effort

8 CVEs tagged to italtel / embrace0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-31842

Published Aug 20, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31843

Published May 23, 2024

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allow…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31847

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31845

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31844

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31840

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31846

Published Apr 19, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31841

Published Apr 19, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1