MidnightBSD

Advisories for sematell

CVE-2024-48905

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 3.9 5.2

Products Affected

Vendor Product Version
sematell replyone 7.4.3.0
CVE-2024-48906

Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
sematell replyone 7.4.3.0
CVE-2024-48907

Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

Products Affected

Vendor Product Version
sematell replyone 7.4.3.0