Product
eramba
10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55462
CVE-2023-36255
CVE-2022-43342
CVE-2020-28031
CVE-2020-25105
CVE-2020-25104
CVE-2018-7997
CVE-2018-7996
CVE-2018-7894
CVE-2018-7741
all versions
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be refl
all versions
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via
all versions
A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute ar
all versions
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated user
all versions
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
all versions
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the f
all versions
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV fil
all versions
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
all versions
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search
all versions
Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.