Skip to main content

Vendor/product archive

oceanicsoft / valeapp CVEs

Beta · best-effort

5 CVEs tagged to oceanicsoft / valeapp2 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-8644

Published Sep 27, 2024

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This i…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8643

Published Sep 27, 2024

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8609

Published Sep 27, 2024

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects ValeApp: before v2.0.0.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8608

Published Sep 27, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS. This issue affects ValeAp…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8607

Published Sep 27, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection. This issue affects ValeApp: b…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1