Skip to main content

Vendor/product archive

ovaledge / ovaledge CVEs

Beta · best-effort

8 CVEs tagged to ovaledge / ovaledge1 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-30361

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclose…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30360

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone p…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30359

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30358

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30357

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is r…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30356

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30355

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-30354

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclos…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1