Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sahi Pro MEDIUM 6.1
CVE-2019-13066

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updatin…

No fix yet
Fix from $1,600 2019-10-29
Sahi Pro HIGH 7.5
CVE-2019-13063EPSS 27%

Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_…

No fix yet
Fix from $1,950 2019-09-23
Sahi Pro CRITICAL 9.8
CVE-2019-15102

An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication …

Fix: after 8.0.0
Fix from $2,300 2019-09-06
Sahi Pro CRITICAL 9.8
CVE-2019-13597EPSS 14%

_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca…

No fix yet
Fix from $2,300 2019-07-14
Sahi Pro CRITICAL 9.8
CVE-2018-20469EPSS 19%

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can b…

Fix: after 8.0.0
Fix from $2,300 2019-06-17
Sahi Pro HIGH 7.5
CVE-2018-20470EPSS 46%

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web repor…

Fix: after 8.0.0
Fix from $1,950 2019-06-17
Sahi Pro MEDIUM 5.4
CVE-2018-20472

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.

Fix: after 8.0.0
Fix from $1,600 2019-06-17
Sahi Pro HIGH 8.8
CVE-2018-20468

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV inje…

Fix: after 8.0.0
Fix from $1,950 2019-06-17