VendorsXpand-itwrite-back_manager2.3.1
Vulnerabilities

Xpand-it Write-back Manager 2.3.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-27168
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
Published 2024-01-19 · Modified
9.8EPSS 0.013
CVE-2023-27172
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
Published 2023-12-20 · Modified
9.1EPSS 0.007
CVE-2023-27170
Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
Published 2023-10-26 · Modified
7.5EPSS 0.009
CVE-2023-27169
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Published 2023-09-12 · Modified
6.5EPSS 0.003