Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-36348 | 1 Codekop | 1 Codekop | 2024-02-28 | N/A | 8.8 HIGH |
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | |||||
CVE-2023-36345 | 1 Codekop | 1 Codekop | 2024-02-28 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges. | |||||
CVE-2023-36347 | 1 Codekop | 1 Codekop | 2024-02-28 | N/A | 7.5 HIGH |
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. | |||||
CVE-2023-36346 | 1 Codekop | 1 Codekop | 2024-02-28 | N/A | 6.1 MEDIUM |
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php. |