2 results (0.002 seconds)

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 1

A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the file /sysmanage/sysmanageajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/rockersiyuan/CVE/blob/main/Smart%20S20.md https://vuldb.com/?ctiid.252993 https://vuldb.com/?id.252993 https://vuldb.com/?submit.274042 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updateos.php of the component HTTP POST Request Handler. The manipulation of the argument 1_file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/flyyue2001/cve/blob/main/smart_sql_updateos.md https://vuldb.com/?ctiid.247154 https://vuldb.com/?id.247154 https://vuldb.com/?submit.241172 • CWE-434: Unrestricted Upload of File with Dangerous Type •