Home/Product/sapplica sentrifugo
Product

sapplica sentrifugo

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-29879
all versions
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'b
7.1HIGH
CVE-2024-29878
all versions
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'description' par
7.1HIGH
CVE-2024-29877
all versions
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'exp
7.1HIGH
CVE-2024-29876
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The
9.8CRITICAL
CVE-2024-29875
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' pa
9.8CRITICAL
CVE-2024-29874
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parame
9.8CRITICAL
CVE-2024-29873
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' param
9.8CRITICAL
CVE-2024-29872
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploit
9.8CRITICAL
CVE-2024-29871
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updat
9.8CRITICAL
CVE-2024-29870
all versions
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' param
9.8CRITICAL
CVE-2023-29770
all versions
In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without ext
8.8HIGH
CVE-2020-28365
all versions
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP heade
6.1MEDIUM
CVE-2020-26805
all versions
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint -- /sentrifugo/index.php/empadditionaldetails/edit/use
7.2HIGH
CVE-2020-26804
all versions
In Sentrifugo 3.2, users can share an announcement under "Organization - Announcements" tab. Also, in this page, users can upload
8.8HIGH
CVE-2020-26803
all versions
In Sentrifugo 3.2, users can upload an image under "Assets - Add" tab. This "Upload Images" functionality is suffered from "Unrest
8.8HIGH
CVE-2020-10218
all versions
A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of
6.5MEDIUM
CVE-2019-16059
all versions
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at i
8.8HIGH
CVE-2019-15814
all versions
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
5.4MEDIUM
CVE-2019-15813
all versions
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary cod
8.8HIGH
CVE-2018-15873
all versions
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
9.8CRITICAL
threatengine.sh