Filtered by vendor Mobatime
Subscribe
Total
5 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-3066 | 1 Mobatime | 1 Amxgt 100 | 2024-11-21 | N/A | 8.1 HIGH |
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20. | |||||
CVE-2023-3065 | 1 Mobatime | 1 Amxgt 100 | 2024-11-21 | N/A | 9.1 CRITICAL |
Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20. | |||||
CVE-2023-3064 | 1 Mobatime | 1 Amxgt 100 | 2024-11-21 | N/A | 7.5 HIGH |
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20. | |||||
CVE-2023-3033 | 1 Mobatime | 1 Mobatime Web Application | 2024-11-21 | N/A | 6.8 MEDIUM |
Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22. | |||||
CVE-2023-3032 | 1 Mobatime | 1 Mobatime Web Application | 2024-11-21 | N/A | 8.1 HIGH |
Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22. |