Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2020-11597

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.
Attacker Value
Unknown

CVE-2020-11588

Disclosure Date: April 06, 2020 (last updated November 27, 2024)
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths.
Attacker Value
Unknown

CVE-2020-11593

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
Attacker Value
Unknown

CVE-2020-11598

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.