Showing 1 vulnerability on this page for CEVAS

Signals CISA KEV Ransomware Nuclei
Johnson Controls vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CEVAS

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.

CWE-79Oct 28, 2022
CVSS10.0v3.1EPSS0.433%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX