Skip to main content

Vendor archive

yellowfinbi CVEs

Beta · best-effort

5 CVEs tagged to vendor yellowfinbi1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-19586

Published Sep 14, 2022

Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36389

Published Oct 14, 2021

In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially cra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36388

Published Oct 14, 2021

In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specia…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36387

Published Oct 14, 2021

In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the pa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1