vendor:
Virtual Support Office-XP
by:
AmnPardaz Security Research Team
7.5
CVSS
HIGH
Broken Authentication, Session Management, Injection Flaws
CWE
Product Name: Virtual Support Office-XP
Affected Version From: 3.0.27
Affected Version To: 3.0.29
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Virtual Support Office-XP Multiple Vulnerabilities
An attacker can have access to classified information, register users without supervision, create admin user, perform SQL injection to obtain passwords and other information.