VendorsSetelsa-securityconacwin3.7.1.2
Vulnerabilities

Setelsa-security Setelsa Security Conacwin 3.7.1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-4037
SQL injection in Setelsa Security ConacWin
Published 2023-10-04 · Modified
9.9EPSS 0.003
CVE-2020-25068
Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.
Published 2020-09-03 · Modified
7.5EPSS 0.039