2
CVE-2024-45832 - Ossur Mobile Logic Application Use of Hard-coded Credentials
Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile application. An attacker could access unauthorized information.
2
CVE-2024-54681 - Ossur Mobile Logic Application Command Injection
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
5.6
CVE-2024-53683 - Ossur Mobile Logic Application Exposure of Sensitive System Information to an Unauthorized Control β¦
A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.
6.3
CVE-2024-26153 - ETIC Telecom Remote Access Server (RAS) Cross-Site Request Forgery
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denβ¦
6.1
CVE-2024-26155 - ETIC Telecom Remote Access Server (RAS) Cleartext Transmission of Sensitive Information
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection to the ETIC RAS ssh server, which could enaβ¦
4.8
CVE-2024-26154 - ETIC Telecom Remote Access Server (RAS) Cross-site Scripting
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
5.3
CVE-2024-26157 - ETIC Telecom Remote Access Server (RAS) Cross-site Scripting
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method under view parameter. The ETIC RAS web server uses dynamic pages that get their input from the client side and reflect the input in their respβ¦
4.8
CVE-2024-26156 - ETIC Telecom Remote Access Server (RAS) Cross-site Scripting
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the clieβ¦
5.3
CVE-2025-0531 - code-projects Chat System leaveroom.php sql injection
A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/leaveroom.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the β¦
5.3
CVE-2025-0530 - code-projects Job Recruitment _feedback_system.php cross site scripting
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/_feedback_system.php. The manipulation of the argument type leads to cross site scripting. The attack can be initiated remotely. The exploitβ¦