Skip to main content

Vendor/product archive

vembu / offsite_dr CVEs

Beta · best-effort

4 CVEs tagged to vembu / offsite_dr3 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-26474

Published Jun 8, 2021

Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26473

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the cont…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26471

Published Jun 8, 2021

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1