Showing 4 vulnerabilities on this page for Journyx (jtime)

Signals CISA KEV Ransomware Nuclei
Journyx vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Journyx Unauthenticated XML External Entities Injection

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

CWE-611Aug 7, 20241 related artifact
CVSS7.5v3.1EPSS32.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Journyx Reflected Cross Site Scripting

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

CWE-79CWE-81Aug 7, 20241 related artifact
CVSS6.1v3.1EPSS0.75%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Journyx Authenticated Remote Code Execution

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

CWE-94CWE-95Aug 7, 2024
CVSS8.8v3.1EPSS0.953%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Journyx Unauthenticated Password Reset Bruteforce

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

CVSS9.8v3.1EPSS0.717%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX