Vulnerabilities (CVE)

Filtered by vendor Sahipro Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13066 1 Sahipro 1 Sahi Pro 2019-11-06 4.3 MEDIUM 6.1 MEDIUM
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.
CVE-2018-20472 1 Sahipro 1 Sahi Pro 2019-06-18 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.