Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-28025

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Attacker Value
Unknown

CVE-2021-27783

Disclosure Date: May 19, 2022 (last updated October 07, 2023)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Attacker Value
Unknown

CVE-2021-27780

Disclosure Date: May 09, 2022 (last updated October 07, 2023)
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Attacker Value
Unknown

CVE-2021-27781

Disclosure Date: May 09, 2022 (last updated October 07, 2023)
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.