5.3

CVSS4.0

CVE-2025-7877 - Metasoft 美特软件 MetaCRM sendfile.jsp unrestricted upload

A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processing of the file sendfile.jsp. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…

📅 Published: July 20, 2025, 8:02 a.m. 🔄 Last Modified: Aug. 27, 2025, 5:18 p.m.

5.3

CVSS4.0

CVE-2025-7876 - Metasoft 美特软件 MetaCRM download.jsp AnalyzeParam deserialization

A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of the file download.jsp. The manipulation of the argument p leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to …

📅 Published: July 20, 2025, 7:44 a.m. 🔄 Last Modified: Aug. 27, 2025, 5:29 p.m.

6.9

CVSS4.0

CVE-2025-7875 - Metasoft 美特软件 MetaCRM debug.jsp improper authentication

A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…

📅 Published: July 20, 2025, 7:14 a.m. 🔄 Last Modified: Aug. 27, 2025, 5:32 p.m.

6.9

CVSS4.0

CVE-2025-7874 - Metasoft 美特软件 MetaCRM env.jsp information disclosure

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /env.jsp. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the p…

📅 Published: July 20, 2025, 7:02 a.m. 🔄 Last Modified: Aug. 27, 2025, 5:50 p.m.

5.3

CVSS4.0

CVE-2025-7873 - Metasoft 美特软件 MetaCRM mcc_login.jsp sql injection

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file mcc_login.jsp. The manipulation of the argument workerid leads to sql injection. The attack can be launched remotely. The exploit …

📅 Published: July 20, 2025, 6:44 a.m. 🔄 Last Modified: Aug. 27, 2025, 5:52 p.m.

5.1

CVSS4.0

CVE-2025-7872 - Portabilis i-Diario justificativas-de-falta cross site scripting

A vulnerability was found in Portabilis i-Diario 1.5.0 and classified as problematic. This issue affects some unknown processing of the file /justificativas-de-falta. The manipulation of the argument Justificativa leads to cross site scripting. The attack may be initiated remotely. The exploit has …

📅 Published: July 20, 2025, 6:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:39 p.m.

5.1

CVSS4.0

CVE-2025-7871 - Portabilis i-Diario conteudos cross site scripting

A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of the argument filter[by_description] leads to cross site scripting. The attack can be initiated remotely. The exploit has bee…

📅 Published: July 20, 2025, 6:02 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:39 p.m.

5.1

CVSS4.0

CVE-2025-7870 - Portabilis i-Diario justificativas-de-falta Endpoint cross site scripting

A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possible to initiate the attack remotely. The exp…

📅 Published: July 20, 2025, 5:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:39 p.m.

5.1

CVSS4.0

CVE-2025-7869 - Portabilis i-Educar Turma Module educar_turma_tipo_det.php cross site scripting

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file intranet/educar_turma_tipo_det.php?cod_turma_tipo=ID of the component Turma Module. The manipulation of the argument nm_tipo leads to c…

📅 Published: July 20, 2025, 5:02 a.m. 🔄 Last Modified: Aug. 13, 2025, 2:42 p.m.

5.1

CVSS4.0

CVE-2025-7868 - Portabilis i-Educar Calendar educar_calendario_dia_motivo_cad.php cross site scripting

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. The manipulation of the argument Motivo/descricao results in cross site scripting. It is possible to l…

📅 Published: July 20, 2025, 4:32 a.m. 🔄 Last Modified: Sept. 27, 2025, 12:28 a.m.
Total resulsts: 349182
Page 4585 of 34,919
« previous page » next page
Filters