VendorsUatechbadaso2.9.7
Vulnerabilities

Uatech Group (Uasoft) Badaso 2.9.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-38969
Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function.
Published 2023-08-28 · Modified
5.4EPSS 0.007
CVE-2023-38974
A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
Published 2023-08-25 · Modified
5.4EPSS 0.005
CVE-2023-38973
A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
Published 2023-08-25 · Modified
5.4EPSS 0.004