Vendors42Gearssuremdmany version
Vulnerabilities

42Gears SureMDM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-15658
An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user. This is caused by the session validation occurring after the initial markup is loaded. This results in a list of unprotected API endpoints that disclose call logs, SMS logs, and user-account data.
Published 2019-02-05 · Modified
7.5EPSS 0.018
CVE-2018-15656
An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base64 encoded e-mail address, to receive confirmation as to whether a user account exists in the system with the specified e-mail address. The request must be made with an "apiKey" value in the "ApiKey" header.
Published 2019-02-05 · Modified
7.5EPSS 0.016
CVE-2018-15657
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
Published 2019-02-05 · Modified
7.31 PoCEPSS 0.016
CVE-2018-15655
An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
Published 2019-02-05 · Modified
6.5EPSS 0.014
CVE-2018-15659
An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possible.
Published 2019-02-05 · Modified
6.5EPSS 0.014
CVE-2023-3897
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
Published 2023-07-25 · Modified
5.31 PoCEPSS 0.031