Vendors1eplatformall versions
Vulnerabilities

1e Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-45163
1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution
Published 2023-11-06 · Modified
9.9EPSS 0.009
CVE-2023-45161
1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution
Published 2023-11-06 · Modified
9.9EPSS 0.008
CVE-2023-5964
1E-Exchange-DisplayMessage instruction allows for arbitrary code execution
Published 2023-11-06 · Modified
9.9EPSS 0.008
CVE-2023-45162
Blind SQL vulnerability in 1E platform
Published 2023-10-13 · Modified
9.9EPSS 0.006
CVE-2025-1683
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
Published 2025-03-12 · Analyzed
7.8EPSS 0.002
CVE-2024-7211
The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
Published 2024-08-01 · Modified
6.1EPSS 0.002