CVE-2023-37220
Published Sep 3, 2023Synel Terminals - CWE-494: Download of Code Without Integrity Check
Vendor archive
8 CVEs tagged to vendor synel — 1 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.
Synel Terminals - CWE-494: Download of Code Without Integrity Check
Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the…
SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" param…
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Emp…
The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.