Jake Rawlins

2 exploits Active since Mar 2020
CVE-2019-18626 WRITEUP MEDIUM WRITEUP
Harris Ormed Self Service <2019.1.4 - Info Disclosure
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.
CVSS 4.3
CVE-2023-6080 WRITEUP HIGH WRITEUP
Lakesidesoftware Systrack Lsiagent < 11.0 - Privilege Escalation
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
CVSS 7.8