MidnightBSD

Advisories for saltos

CVE-2018-18760 MEDIUM

RhinOS 3.0 build 1190 allows CSRF.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
saltos rhinos 3.0
CVE-2018-18761 HIGH

SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
saltos saltos 3.1
CVE-2018-18762 MEDIUM

SaltOS 3.1 r8126 contains a database download vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
saltos saltos 3.1
CVE-2018-18763 HIGH

SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
saltos saltos 3.1