Vulnerabilities (CVE)

Filtered by vendor Codekop Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36348 1 Codekop 1 Codekop 2024-02-28 N/A 8.8 HIGH
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
CVE-2023-36345 1 Codekop 1 Codekop 2024-02-28 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
CVE-2023-36347 1 Codekop 1 Codekop 2024-02-28 N/A 7.5 HIGH
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
CVE-2023-36346 1 Codekop 1 Codekop 2024-02-28 N/A 6.1 MEDIUM
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.