xpand-it has 4 CVEs on record between 2023 and 2024. The median CVSS is 8.3 (high), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2023-27168Critical· 9.8An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.66CVE-2023-27170High· 7.5Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.53CVE-2023-27172Critical· 9.1Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens50CVE-2023-27169Medium· 6.5Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.36
xpand-it vulnerabilities
CVEs affecting xpand-it, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2023-27168Critical· 9.8PoCAn arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.
CVE-2023-27172Critical· 9.1Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
CVE-2023-27170High· 7.5PoCXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
CVE-2023-27169Medium· 6.5Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.