Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Moderate

CVE-2022-22963

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Attacker Value
Unknown

CVE-2023-31302

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.
Attacker Value
Unknown

CVE-2023-31300

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
Attacker Value
Unknown

CVE-2023-31295

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
Attacker Value
Unknown

CVE-2023-31299

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.
Attacker Value
Unknown

CVE-2023-31296

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
Attacker Value
Unknown

CVE-2023-31294

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
Attacker Value
Unknown

CVE-2023-31293

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.
Attacker Value
Unknown

CVE-2023-31301

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.
Attacker Value
Unknown

CVE-2023-31298

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.