i-doit
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting i-doit.
- CVE-2019-25582i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameter6.5
- CVE-2019-25581i-doit CMDB 1.12 SQL Injection via objGroupID Parameter8.2
- CVE-2024-8750Cross-site Scripting vulnerability in Idoit pro5.4
- CVE-2024-8749SQL Injection vulnerability in Idoit pro8.8
- CVE-2023-46003I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.5.4
- CVE-2023-37755i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password an...9.8
- CVE-2023-37756I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.9.8
- CVE-2023-37739i-doit Pro v25 and below was discovered to be vulnerable to path traversal.6.5
- CVE-2023-34830i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.5.4
- CVE-2021-3151i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web script or HTML via C__MONITORING__CONFIG__TITLE,...5.4
- CVE-2020-13825A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode pa...6.1
- CVE-2020-13826A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.8.8
- CVE-2019-1010248Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can ex...9.8
- CVE-2019-6965An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.6.1
- CVE-2018-20159i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files...7.2