Home/Product/itpison omicard edm
Product

itpison omicard edm

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-48373
all versions
ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthentica
7.5HIGH
CVE-2023-48372
all versions
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exp
9.8CRITICAL
CVE-2023-48371
all versions
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote at
9.8CRITICAL
CVE-2023-32753
all versions
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker c
9.8CRITICAL
CVE-2023-28700
all versions
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network
6.8MEDIUM
CVE-2022-35216
>= 5.8 and <= 6.0
OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this
7.5HIGH
CVE-2022-32965
>= 5.8 and <= 6.0
OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to
9.8CRITICAL
CVE-2022-32964
>= 5.8 and <= 6.0
OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary S
9.8CRITICAL
CVE-2022-32963
>= 5.8 and <= 6.0
OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this v
7.5HIGH
threatengine.sh