Home/Product/scriptcase
Product

scriptcase

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-46084
<= 9.10.023
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
8.0HIGH
CVE-2024-46082
<= 9.10.023
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.
5.4MEDIUM
CVE-2024-46080
<= 9.10.023
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
8.0HIGH
CVE-2024-46083
<= 9.10.023
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads us
5.4MEDIUM
CVE-2024-46081
<= 9.10.023
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in
5.4MEDIUM
CVE-2024-46079
<= 9.10.023
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
6.1MEDIUM
CVE-2024-8942
all versions
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, af
6.3MEDIUM
CVE-2024-8941
all versions
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage”
7.5HIGH
CVE-2024-8940
all versions
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/l
10.0CRITICAL
CVE-2022-32199
<= 9.9.008
db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequen
6.5MEDIUM
threatengine.sh