Known Vulnerabilities for Sitos Six by Sitos
Listed below are 6 of the newest known vulnerabilities associated with "Sitos Six" by "Sitos".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-15751 json | An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uplo... | 9.8 - CRITICAL | 2019-10-07 | 2019-10-09 |
| CVE-2019-15750 json | A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject a... | 6.1 - MEDIUM | 2019-10-07 | 2019-10-09 |
| CVE-2019-15749 json | SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm th... | 6.5 - MEDIUM | 2019-10-07 | 2019-10-09 |
| CVE-2019-15748 json | SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected ... | 9.8 - CRITICAL | 2019-10-07 | 2019-10-09 |
| CVE-2019-15747 json | SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadmi... | 8.8 - HIGH | 2019-10-07 | 2019-10-09 |
| CVE-2019-15746 json | SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the runni... | 9.8 - CRITICAL | 2019-10-07 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sitos | Sitos Six | 6.2.1 |