VembuCVEs & Vulnerabilities

7 CVEs affecting Vembu products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

bdr suite 5offsite dr 5storegrid 2
CVE-2021-43458HIGH

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

4 Apr 2022
7.8
CVSS
CVE-2021-26474HIGH

Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)

8 Jun 2021
8.8
CVSS
CVE-2021-26473CRITICAL

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.

8 Jun 2021
9.8
CVSS
CVE-2021-26472CRITICAL

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.

8 Jun 2021
9.8
CVSS
CVE-2021-26471CRITICAL

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.

8 Jun 2021
9.8
CVSS
CVE-2014-10079MEDIUMpoc

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.

23 Feb 2019
5.3
CVSS
CVE-2014-10078MEDIUMpoc

Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.

23 Feb 2019
6.1
CVSS
← PrevPage 1 / 1Next →