Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Priority – CWE-552: Files or Directories Accessible to External Parties
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - de…
Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…