VendorsQuadbaseespressdashboard7.0
Vulnerabilities

Quadbase EspressDashboard 7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-24985
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.
Published 2021-03-15 · Modified
8.1EPSS 0.011
CVE-2020-24982
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
Published 2021-03-15 · Modified
4.3EPSS 0.004