Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-38771

The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.

CVE
#sql#vulnerability#auth

****Vendor of Product:** Transtek******Affected Product:** Mojodat FAM (Fixed Asset Management)******Affected Component:** Mobile Appicaltion******Vulnerabilities Details:** **

CVE ID

Version

Problem Type

Description

CVE-2022-38768

2.4.6

Incorrect Access Control

The mobile application allows remote attackers to bypass authorization.

CVE-2022-38769

2.4.6

Incorrect Access Control

The mobile application allows remote attackers to fetch cleartext passwords upon a successful login request.

CVE-2022-38770

2.4.6

Incorrect Access Control

The mobile application allows remote attackers to fetch other users’ data upon a successful login request.

CVE-2022-38771

2.4.6

SQL Injection

The mobile application allows remote attackers to send SCRIPT tags as injected input to the API request.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda