SandlineCVEs & Vulnerabilities
3 CVEs affecting Sandline products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
centraleyezer 3
CVE-2019-12311MEDIUM
Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.
18 Nov 2019
6.1
CVSS
CVE-2019-12299MEDIUM
Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.
18 Nov 2019
6.1
CVSS
CVE-2019-12271CRITICAL
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.
18 Nov 2019
9.8
CVSS
← PrevPage 1 / 1Next →