3 results (0.004 seconds)

CVSS: 4.8EPSS: 0%CPEs: 2EXPL: 0

Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser • https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. • https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. SLM presenta un problema de seguridad con las rutas de servicio no Citadas/Confiables de Windows. Todas las instalaciones versiones 9.x.x anteriores a 9.20.1 deben ser parcheadas • https://community.snowsoftware.com/s/feed/0D5690000BsNCO6CQO • CWE-428: Unquoted Search Path or Element •