Vulnerabilities (CVE)

Filtered by vendor Emlsoft Project Subscribe
Filtered by product Emlsoft
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14965 1 Emlsoft Project 1 Emlsoft 2018-10-04 6.8 MEDIUM 8.8 HIGH
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.
CVE-2018-14966 1 Emlsoft Project 1 Emlsoft 2018-10-04 6.8 MEDIUM 8.8 HIGH
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.
CVE-2018-14967 1 Emlsoft Project 1 Emlsoft 2018-10-04 6.5 MEDIUM 8.8 HIGH
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.user.php has SQL Injection via the numPerPage parameter.