Known Vulnerabilities for products from Ocomon Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Ocomon Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-33559 json | A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary cod... | 8.8 - HIGH | 2023-10-26 | 2023-11-07 |
| CVE-2023-33558 json | An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obta... | 7.5 - HIGH | 2023-10-26 | 2023-11-03 |
| CVE-2022-41391 json | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. | 9.8 - CRITICAL | 2022-10-13 | 2022-10-17 |
| CVE-2022-41390 json | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. | 9.8 - CRITICAL | 2022-10-13 | 2022-10-17 |
| CVE-2022-40798 json | OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the sa... | 7.5 - HIGH | 2022-10-19 | 2022-10-21 |