JC175

3 exploits Active since Jul 2022
CVE-2022-32119 NOMISEC HIGH WORKING POC
Arox School Erp Pro - Unrestricted File Upload
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
17 stars
CVSS 8.8
CVE-2022-32118 NOMISEC MEDIUM WORKING POC
Arox School Erp Pro - XSS
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.
1 stars
CVSS 6.1
CVE-2022-37177 NOMISEC HIGH WRITEUP
Hirevue Hiring Platform - Broken Cryptographic Algorithm
HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent with CVE ID assignment rules for cloud services, and no product with version V1.0 exists. Furthermore, the rail-fence cipher has been removed, and TLS 1.2 is now used for encryption.
1 stars
CVSS 7.5