An attacker could terminate the service of Sparx Pro Cloud Server. By sending a specially crafted SQL query, aDenial of Service (DoS) attack could beperformed). The issue has been identified in versions up to and including 6.1. Other versions have not been tested and may also be vulnerable.
CVSS v4: 7.1
Attack Complexity: Low
Attack Requirements: None
Privileges Required: Low
Confidentiality (VC): None
Integrity (VI): None
Availability (VA): High
Confidentiality (SC): None
Integrity (SI): None
Sparx Pro Cloud Server is vulnerable to a Race Condition in the extention:data_api/dl_internal_artifact.php. The application retrieves object properties (param: guid) and stores the response locally (DIR) under a name and content controlled by anattacker with access to the repository. he file is deleted after processing, but the transmission delay (large file/slow connection) creates a race condition. Simply sending a secon request to execute a malicious PHP file during this time results in remote code execution. The issue has been identified in versions up to and including 6.1. Other versions have not been tested and may also be vulnerable.
CVSS v4: 7.7
Attack Complexity: High
Attack Requirements: Present
Privileges Required: Low
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): High
Confidentiality (SC): Low
Integrity (SI): Low
Availability (SA): Low
An authenticated attacker can modify the behavior of the Sparx client (e.g., using a debugger) and log in as any other user or administrator. Thiscould then make changes to the repository. The issue has been identified in versions up to and including 17.1. Other versions have not been tested and may also be vulnerable.
CVSS v4: 8.7
Attack Requirements: None
Privileges Required: Low
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): High
Confidentiality (SC): None
Integrity (SI): None
Atakujący może wykonać zapytanie SQL bez uwierzytelniania w Sparx Pro Cloud Server. Umożliwia to pominięcie parametru zapytania “model” i wysłanie nazwy w binary blob w żądaniu POST. Problem został zidentyfikowany w wersjach do 6.1 włącznie. Pozostałe wersje nie zostały przetestowane i również mogą być podatne.
CVSS v4: 9.3
Attack Requirements: None
Privileges Required: None
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): Low
Confidentiality (SC): None
Integrity (SI): None
The Sparx Pro Cloud server is vulnerable to a Broken Access Control attack in database communication. Due to a lack of permissions control, any low-privileged user can execute arbitrary SQL queries in the context of the database userThe issue has been identified in versions up to and including 6.1. Other versions have not been tested and may also be vulnerable.
CVSS v4: 8.7
Attack Requirements: None
Privileges Required: Low
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): Low
Confidentiality (SC): None
Pro3W CMS is vulnerable to SQL injection attacks. Improper neutralization of input provided to the login form allows a remote attacker to bypass authentication and gain administrative privileges. This issue was identified in version 1.2.0 of this software. Problem został zidentyfikowany w wersji 1.2.0 tego oprogramowania.
CVSS v4: 9.3
Attack Requirements: None
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): Low
Confidentiality (SC): None
The reporting functionality in Wyn Enterprise allows for code inclusion, but does not sufficiently restrict what code can be included. An attacker can use a low-privileged account to abuse this functionality and execute malicious code, load DLLs, and execute operating system commands on the host system with high-privileged applications. This issue is fixed in version 8.0.00204.0
CVSS v4: 8.7
Attack Requirements: None
Confidentiality (VC): High
Integrity (VI): High
Availability (VA): High
Confidentiality (SC): None
A vulnerability in Ant Media Server Community Edition allows manipulation of headers in HTTP requests, enabling an unauthorized user to access all API functionalities (except for administrative ones) of the Ant Media Server Community Edition.
A directory traversal vulnerability in the file upload functionality in Gotenberg - before version 6.2.1 allows an attacker to upload and overwrite arbitrary writable files outside the intended directory.
This may lead to performed, modification of application behavior or code execution..

