VendorsSapplicasentrifugoall versions
Vulnerabilities

Sapplica Sentrifugo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2018-15873
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
Published 2018-08-28 · Modified
9.8EPSS 0.011
CVE-2024-29875
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.009
CVE-2024-29874
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.009
CVE-2024-29871
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.009
CVE-2024-29870
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.009
CVE-2024-29876
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.008
CVE-2024-29872
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.008
CVE-2024-29873
SQL injection vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
9.8EPSS 0.008
CVE-2020-26803
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
Published 2020-11-12 · Modified
8.8EPSS 0.014
CVE-2020-26804
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
Published 2020-11-12 · Modified
8.8EPSS 0.014
CVE-2023-29770
In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.
Published 2023-11-27 · Modified
8.8EPSS 0.009
CVE-2019-16059
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.
Published 2019-09-06 · Modified
8.8EPSS 0.006
CVE-2020-26805
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability. Attacker can inject SQL commands into query, read data from database or write data into the database.
Published 2020-11-12 · Modified
7.2EPSS 0.015
CVE-2024-29877
Cross-Site Scripting (XSS) vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
7.1EPSS 0.005
CVE-2024-29878
Cross-Site Scripting (XSS) vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
7.1EPSS 0.005
CVE-2024-29879
Cross-Site Scripting (XSS) vulnerability in Sentrifugo
Published 2024-03-21 · Analyzed
7.1EPSS 0.005
CVE-2020-10218
A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.
Published 2020-03-13 · Modified
6.5EPSS 0.012
CVE-2020-28365
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator looks at logs, the payload is executed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2020-12-30 · Modified
6.1EPSS 0.007