Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2022-38619
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
0
Attacker Value
Unknown
CVE-2022-38618
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
0
Attacker Value
Unknown
CVE-2022-38617
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
0
Attacker Value
Unknown
CVE-2022-38616
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
0
Attacker Value
Unknown
CVE-2022-38615
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
0
Attacker Value
Unknown
CVE-2022-38614
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
0
Attacker Value
Unknown
CVE-2022-38613
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
0
Attacker Value
Unknown
CVE-2022-35554
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.
0
Attacker Value
Unknown
CVE-2018-15208
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
0
Attacker Value
Unknown
CVE-2018-15207
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
0