Vulnerabilities (CVE)

Filtered by vendor Primasystems Subscribe
Filtered by product Flexair
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-7671 1 Primasystems 1 Flexair 2020-02-10 3.5 LOW 5.4 MEDIUM
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CVE-2019-7280 1 Primasystems 1 Flexair 2019-07-31 4.0 MEDIUM 4.3 MEDIUM
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.