VendorsMida Solutionseframeworkany version
Vulnerabilities

Mida Solutions eFramework any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-15920
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
Published 2020-07-24 · Modified
10.01 PoCEPSS 0.982
CVE-2020-15922
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
Published 2020-07-24 · Modified
10.01 PoCEPSS 0.573
CVE-2020-15921
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
Published 2020-07-24 · Modified
9.81 PoCEPSS 0.183
CVE-2020-15923
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
Published 2020-07-24 · Modified
7.8EPSS 0.033
CVE-2020-15924
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.
Published 2020-07-24 · Modified
7.5EPSS 0.019
CVE-2020-15919
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
Published 2020-07-24 · Modified
6.1EPSS 0.009
CVE-2020-15918
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
Published 2020-07-24 · Modified
5.4EPSS 0.006