VulnSea

xpand-it has 4 CVEs on record between 2023 and 2024. The median CVSS is 8.3 (high), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.3
Publish → KEV
Last 90 days
0 prev 0

Products

  • write-back_manager 4
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

xpand-it vulnerabilities

CVEs affecting xpand-it, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2023-27168Critical· 9.8PoC
2y ago

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

Abyssalxpand-it · write-back_managerEPSS 1.3%via NVD
CVE-2023-27172Critical· 9.1
2y ago

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.

Midnightxpand-it · write-back_managerEPSS 0.69%via NVD
CVE-2023-27170High· 7.5PoC
2y ago

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

Midnightxpand-it · write-back_managerEPSS 0.87%via NVD
CVE-2023-27169Medium· 6.5
3y ago

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

Sunlitxpand-it · write-back_managerEPSS 0.32%via NVD
xpand-it vulnerabilities (CVEs) · VulnSea