Skip to main content

Vendor/product archive

sitos / sitos_six CVEs

Beta · best-effort

6 CVEs tagged to sitos / sitos_six3 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2019-15751

Published Oct 7, 2019

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15750

Published Oct 7, 2019

A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15749

Published Oct 7, 2019

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15748

Published Oct 7, 2019

SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the uploa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15747

Published Oct 7, 2019

SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to insufficient checks on the serve…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15746

Published Oct 7, 2019

SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1