Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-8161

Disclosure Date: August 26, 2024 (last updated February 26, 2025)
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database.
0
Attacker Value
Unknown

CVE-2024-2728

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol.
0
Attacker Value
Unknown

CVE-2024-2727

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
0
Attacker Value
Unknown

CVE-2024-2726

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
0
Attacker Value
Unknown

CVE-2024-2725

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.
0
Attacker Value
Unknown

CVE-2024-2724

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0
Attacker Value
Unknown

CVE-2024-2723

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0
Attacker Value
Unknown

CVE-2024-2722

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
0