Showing 2 vulnerabilities on this page for Portal del Empleado

Signals CISA KEV Ransomware Nuclei
Summar Software vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter “cctl00$ContentPlaceHolder1$fuAdjunto” in “/MemberPages/ntf_absentismo.aspx”.

CWE-434Sep 18, 2025
CVSS5.3v4.0EPSS0.268%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL injection vulnerability in Summar Software´s Portal del Empleado

SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve, create, update, and delete the database by sending a POST request using the parameter “ctl00$ContentPlaceHolder1$filtroNombre” in “/MemberPages/quienesquien.aspx”.

CWE-89Sep 18, 2025
CVSS8.7v4.0EPSS0.588%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX