Vulnerabilities (CVE)

Filtered by vendor Servisnet Subscribe
Filtered by product Tessa
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22831 1 Servisnet 1 Tessa 2024-02-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.
CVE-2022-22832 1 Servisnet 1 Tessa 2024-02-28 10.0 HIGH 9.8 CRITICAL
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
CVE-2022-22833 1 Servisnet 1 Tessa 2024-02-28 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.