Skip to main content

Vendor archive

quadbase CVEs

Beta · best-effort

6 CVEs tagged to vendor quadbase0 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-24985

Published Mar 15, 2021

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc param…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24982

Published Mar 15, 2021

An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address asso…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24984

Published Mar 11, 2021

An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicio…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24983

Published Mar 11, 2021

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9958

Published Jun 24, 2019

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9957

Published Jun 24, 2019

Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. Th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1