Skip to main content

Vendor archive

vembu CVEs

Beta · best-effort

7 CVEs tagged to vendor vembu3 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-43458

Published Apr 4, 2022

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26474

Published Jun 8, 2021

Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26473

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the cont…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26471

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-10079

Published Feb 23, 2019

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10078

Published Feb 23, 2019

Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1