Product
cybelesoft thinfinity virtualui
6 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-46354
CVE-2021-44554
CVE-2021-45092
CVE-2021-44848
CVE-2019-16385
CVE-2019-16384
all versions
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability
< 3.0
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePass
< 3.0
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpat
< 3.0
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests dependi
<= 2.5.17.2
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as dem
<= 2.5.17.2
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside