Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-8161
Disclosure Date: August 26, 2024 (last updated February 26, 2025)
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database.
0
Attacker Value
Unknown
CVE-2024-2728
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol.
0
Attacker Value
Unknown
CVE-2024-2727
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
0
Attacker Value
Unknown
CVE-2024-2726
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
0
Attacker Value
Unknown
CVE-2024-2725
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.
0
Attacker Value
Unknown
CVE-2024-2724
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0
Attacker Value
Unknown
CVE-2024-2723
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0
Attacker Value
Unknown
CVE-2024-2722
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0