VendorsTelaxiusepesiall versions
Vulnerabilities

Telaxius Epesi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2017-8763
Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter.
Published 2017-05-04 · Modified
6.1EPSS 0.008
CVE-2017-14712
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
Published 2017-09-22 · Modified
5.41 PoCEPSS 0.014
CVE-2017-14717
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
Published 2017-09-22 · Modified
5.41 PoCEPSS 0.014
CVE-2017-14715
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
Published 2017-09-22 · Modified
5.4EPSS 0.006
CVE-2017-14716
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
Published 2017-09-22 · Modified
5.4EPSS 0.006
CVE-2017-14713
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
Published 2017-09-22 · Modified
5.4EPSS 0.006
CVE-2017-14714
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
Published 2017-09-22 · Modified
5.4EPSS 0.006