Vulnerabilities (CVE)

Filtered by vendor Overit Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22834 1 Overit 1 Geocall 2022-05-09 6.0 MEDIUM 8.8 HIGH
An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.
CVE-2019-5889 1 Overit 1 Geocall 2020-04-23 5.0 MEDIUM 7.5 HIGH
An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
CVE-2019-5890 1 Overit 1 Geocall 2020-04-23 9.0 HIGH 8.8 HIGH
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions.