Show filters
75 Total Results
Displaying 21-30 of 75
Sort by:
Attacker Value
Unknown

CVE-2021-27930

Disclosure Date: July 06, 2021 (last updated February 22, 2025)
Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).
Attacker Value
Unknown

CVE-2013-2571

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.
Attacker Value
Unknown

CVE-2013-1744

Disclosure Date: January 25, 2020 (last updated November 28, 2024)
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
Attacker Value
Unknown

CVE-2019-15374

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
Attacker Value
Unknown

CVE-2019-15334

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
Attacker Value
Unknown

CVE-2019-15338

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
Attacker Value
Unknown

CVE-2019-15362

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
Attacker Value
Unknown

CVE-2019-18924

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.
Attacker Value
Unknown

CVE-2019-18925

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
Attacker Value
Unknown

CVE-2019-18926

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.