Vulnerabilities (CVE)

Filtered by vendor Midasolutions Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15923 1 Midasolutions 1 Eframework 2020-07-27 7.8 HIGH 7.5 HIGH
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
CVE-2020-15924 1 Midasolutions 1 Eframework 2020-07-27 5.0 MEDIUM 7.5 HIGH
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.