EthicalHCOP

4 exploits Active since Jun 2019
CVE-2020-28413 NOMISEC MEDIUM WORKING POC
Mantisbt < 2.24.4 - SQL Injection
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
CVSS 5.3
CVE-2019-12890 NOMISEC CRITICAL WORKING POC
Redwoodhq - Missing Authentication
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
CVSS 9.8
CVE-2019-12890 EXPLOITDB CRITICAL python WORKING POC
Redwoodhq - Missing Authentication
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
CVSS 9.8
CVE-2020-28413 EXPLOITDB MEDIUM python WORKING POC
Mantisbt < 2.24.4 - SQL Injection
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
CVSS 5.3