Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2020-28365

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator looks at logs, the payload is executed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-26804

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
Attacker Value
Unknown

CVE-2020-26805

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability. Attacker can inject SQL commands into query, read data from database or write data into the database.
Attacker Value
Unknown

CVE-2020-26803

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
Attacker Value
Unknown

CVE-2020-10218

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.
Attacker Value
Unknown

CVE-2019-16059

Disclosure Date: September 06, 2019 (last updated November 27, 2024)
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.
0
Attacker Value
Unknown

CVE-2019-15813

Disclosure Date: September 04, 2019 (last updated November 27, 2024)
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.
Attacker Value
Unknown

CVE-2019-15814

Disclosure Date: September 04, 2019 (last updated November 27, 2024)
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2018-15873

Disclosure Date: August 28, 2018 (last updated November 27, 2024)
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.