Vulnerabilities (CVE)

Filtered by vendor Ajenti Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-25066 1 Ajenti 1 Ajenti 2022-06-15 6.5 MEDIUM 8.8 HIGH
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.
CVE-2018-1000126 1 Ajenti 1 Ajenti 2018-04-11 5.0 MEDIUM 7.5 HIGH
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application.
CVE-2018-1000081 1 Ajenti 1 Ajenti 2018-04-06 5.0 MEDIUM 7.5 HIGH
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter ..
CVE-2018-1000082 1 Ajenti 1 Ajenti 2018-04-06 6.8 MEDIUM 8.8 HIGH
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed..