unilogies Vulnerabilities and Affected Products
Vulnerabilities associated with unilogies/bumsys.
Products
Clear product- unilogies/bumsys9 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-2832HIGH | SQL Injection in unilogies/bumsysSQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0. CWE-89May 22, 2023 | CVSS7.2v3.1 | EPSS0.891% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2551HIGH | PHP Remote File Inclusion in unilogies/bumsysPHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. | CVSS8.8v3.1 | EPSS1.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2552HIGH | Cross-Site Request Forgery (CSRF) in unilogies/bumsysCross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. CWE-352May 5, 2023 | CVSS8.8v3.1 | EPSS0.43% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2554HIGH | External Control of File Name or Path in unilogies/bumsysExternal Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0. CWE-73May 5, 2023 | CVSS7.2v3.1 | EPSS29.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2553MEDIUM | Cross-site Scripting (XSS) - Stored in unilogies/bumsysCross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0. CWE-79May 5, 2023 | CVSS5.4v3.1 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1361MEDIUM | SQL Injection in unilogies/bumsysSQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2. CWE-89Mar 13, 2023 | CVSS6.5v3.1 | EPSS0.751% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1362MEDIUM | Improper Restriction of Rendered UI Layers or Frames in unilogies/bumsysImproper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2. | CVSS6.1v3.1 | EPSS1.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-0995MEDIUM | Cross-site Scripting (XSS) - Stored in unilogies/bumsysCross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1. CWE-79Feb 24, 2023 | CVSS5.4v3.1 | EPSS0.479% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0455HIGH | Unrestricted Upload of File with Dangerous Type in unilogies/bumsysUnrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. CWE-434Jan 26, 2023 | CVSS8.8v3.1 | EPSS5.75% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |