Home/Product/i doit i doit
Product

i doit i doit

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-25582
all versions
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files
6.5MEDIUM
CVE-2019-25581
all versions
i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by
8.2HIGH
CVE-2024-8750
all versions
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session detail
5.4MEDIUM
CVE-2024-8749
all versions
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query
8.8HIGH
CVE-2023-46003
<= 25
I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
5.4MEDIUM
CVE-2023-37756
<= 25
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attacke
9.8CRITICAL
CVE-2023-37755
<= 25
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is
9.8CRITICAL
CVE-2023-37739
<= 25
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
6.5MEDIUM
CVE-2023-34830
<= 24
i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the lo
5.4MEDIUM
CVE-2021-3151
< 1.16.0
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to in
5.4MEDIUM
CVE-2020-13826
<= 1.14.2
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary co
8.8HIGH
CVE-2020-13825
<= 1.14.2
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the
6.1MEDIUM
CVE-2019-1010248
<= 1.12
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The com
9.8CRITICAL
CVE-2019-6965
all versions
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
6.1MEDIUM
CVE-2018-20159
all versions
i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authe
7.2HIGH
CVE-2014-2231
<= 1.2.4
Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrar
CVE-2014-1597
<= 1.2.4
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attacker
CVE-2014-1237
<= 1.2.3
Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary web scrip
CVE-2013-1413
<= 1.0
Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.
threatengine.sh