VendorsCybelesoftthinfinity_workspaceall versions
Vulnerabilities

Cybelesoft Cybele Software Thinfinity Workspace

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.
Published 2024-11-13 · Analyzed
9.8EPSS 0.005
CVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.
Published 2024-11-13 · Analyzed
8.1EPSS 0.005
CVE-2024-40407
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
Published 2024-11-13 · Analyzed
7.5EPSS 0.004
CVE-2024-40408
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
Published 2024-11-13 · Analyzed
7.3EPSS 0.003
CVE-2024-40410
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.
Published 2024-11-13 · Analyzed
4.8EPSS 0.001