📦 Evolution

by Cs Technologies

🔍 What is Evolution?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-29844

CRITICAL CVSS 9.8 Apr 15, 2024

CVE-2024-29844 is a critical authentication bypass vulnerability in Evolution Controller 2.x web interface that allows attackers to log in using default credentials. This affects all Evolution Control...

CVE-2024-29843

HIGH CVSS 7.5 Apr 15, 2024

The Evolution Controller web interface contains an access control vulnerability in the MOBILE_GET_USERS_LIST endpoint that allows unauthenticated attackers to enumerate all users and their access leve...

CVE-2024-29837

HIGH CVSS 8.8 Apr 15, 2024

This vulnerability allows unauthenticated attackers to access administrator functionality in Evolution Controller's web interface when any user is already signed in. It affects Evolution Controller ve...

CVE-2024-29839

HIGH CVSS 7.5 Apr 15, 2024

The Evolution Controller web interface has an access control vulnerability in the DESKTOP_EDIT_USER_GET_CARD endpoint that allows unauthenticated attackers to retrieve card value data for any user. Th...

CVE-2024-29841

HIGH CVSS 7.5 Apr 15, 2024

The Evolution Controller web interface contains an access control vulnerability in the DESKTOP_EDIT_USER_GET_KEYS_FIELDS endpoint that allows unauthenticated attackers to retrieve sensitive keys data ...