VendorsCysoft168super_easy_enterprise_management_systemall versions
Vulnerabilities

Cysoft168 Super Easy Enterprise Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-42679
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
Published 2024-08-15 · Modified
7.8EPSS 0.003
CVE-2024-42678
Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.
Published 2024-08-15 · Modified
6.1EPSS 0.003
CVE-2024-42680
An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark.
Published 2024-08-15 · Modified
5.5EPSS 0.003