Vulnerabilities (CVE)

Filtered by vendor Invernyx Subscribe
Filtered by product Smartcars 3
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33780 1 Invernyx 1 Smartcars 3 2024-02-28 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article.
CVE-2023-28441 1 Invernyx 1 Smartcars 3 2024-02-28 N/A 7.5 HIGH
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly.