Home/Product/eramba
Product

eramba

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55462
all versions
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be refl
6.5MEDIUM
CVE-2023-36255
all versions
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via
8.8HIGH
CVE-2022-43342
all versions
A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute ar
5.4MEDIUM
CVE-2020-28031
all versions
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated user
4.3MEDIUM
CVE-2020-25105
all versions
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
9.8CRITICAL
CVE-2020-25104
all versions
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the f
5.4MEDIUM
CVE-2018-7997
all versions
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV fil
6.1MEDIUM
CVE-2018-7996
all versions
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
6.1MEDIUM
CVE-2018-7894
all versions
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search
6.1MEDIUM
CVE-2018-7741
all versions
Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.
6.1MEDIUM