Skip to main content

Vendor/product archive

artica / integria_ims CVEs

Beta · best-effort

7 CVEs tagged to artica / integria_ims3 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-3834

Published Oct 7, 2021

Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-si…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3833

Published Oct 7, 2021

Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a sp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3832

Published Oct 7, 2021

Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in or…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15091

Published Aug 16, 2019

filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000812

Published Dec 20, 2018

Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password reco…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19829

Published Dec 18, 2018

Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1