Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-49328

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.
Attacker Value
Unknown

CVE-2023-33438

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2021-41932

Disclosure Date: June 06, 2022 (last updated October 07, 2023)
A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc.
Attacker Value
Unknown

CVE-2021-44035

Disclosure Date: December 17, 2021 (last updated October 07, 2023)
Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.
Attacker Value
Unknown

CVE-2010-3125

Disclosure Date: August 26, 2010 (last updated October 04, 2023)
Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .tmx file.
0