ComputrolsCVEs & Vulnerabilities
10 CVEs affecting Computrols products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
Most Affected Products
Computrols CBAS 18.0.0 allows Username Enumeration.
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
Computrols CBAS 18.0.0 has Default Credentials.
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
Computrols CBAS 18.0.0 allows Authentication Bypass.
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
Computrols CBAS 18.0.0 has hard-coded encryption keys.