Filtered by vendor Sentrifugo Subscriptions
Filtered by product Sentrifugo Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-29873 2 Sapplica, Sentrifugo 2 Sentrifugo, Sentrifugo 2025-04-10 9.8 Critical
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2019-15814 1 Sentrifugo 1 Sentrifugo 2024-11-21 N/A
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
CVE-2019-15813 1 Sentrifugo 1 Sentrifugo 2024-11-21 8.8 High
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.