Skip to main content

Vendor/product archive

ocomon_project / ocomon CVEs

Beta · best-effort

5 CVEs tagged to ocomon_project / ocomon2 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-33559

Published Oct 26, 2023

A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33558

Published Oct 26, 2023

An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40798

Published Oct 19, 2022

OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41390

Published Oct 13, 2022

OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1