Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-28898

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.
Attacker Value
Unknown

CVE-2020-25746

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.
Attacker Value
Unknown

CVE-2020-13877

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.