Vulnerabilities (CVE)

Filtered by vendor Businessdnasolutions Subscribe
Filtered by product Topease
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42544 1 Businessdnasolutions 1 Topease 2021-11-30 7.5 HIGH 9.8 CRITICAL
Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.
CVE-2021-42115 1 Businessdnasolutions 1 Topease 2021-11-30 6.4 MEDIUM 9.1 CRITICAL
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.