📦 Ruvaroa

by Ruvar

🔍 What is Ruvaroa?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-25532

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the bt_id parameter at /include/get_dict.aspx, allowing attackers to execute arbitrary SQL commands. This affects organizations...

CVE-2024-25527

CRITICAL CVSS 9.4 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the id parameter at /PersonalAffair/worklog_template_show.aspx. This allows attackers to execute arbitrary SQL commands on the ...

CVE-2024-25530

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the PageID parameter at /WebUtility/get_find_condiction.aspx. This allows attackers to execute arbitrary SQL commands on the da...

CVE-2024-25521

CRITICAL CVSS 9.4 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the get_company.aspx endpoint via the txt_keyword parameter. This allows attackers to execute arbitrary SQL commands on the dat...

CVE-2024-25523

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the file_id parameter at /filemanage/file_memo.aspx. This allows attackers to execute arbitrary SQL commands on the database. O...

CVE-2024-25525

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the filename parameter at /WorkFlow/OfficeFileDownload.aspx. This allows attackers to execute arbitrary SQL commands on the dat...

CVE-2024-25517

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the tbTable parameter at /WebUtility/MF.aspx. This allows attackers to execute arbitrary SQL commands on the database. Organiza...

CVE-2024-25519

CRITICAL CVSS 9.8 May 8, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the idlist parameter at /WorkFlow/wf_work_print.aspx. This allows attackers to execute arbitrary SQL commands on the database. ...

CVE-2024-25509

CRITICAL CVSS 9.4 May 7, 2024

This SQL injection vulnerability in RuvarOA allows attackers to execute arbitrary SQL commands via the sys_file_storage_id parameter in the wf_file_download.aspx endpoint. Successful exploitation coul...

CVE-2024-25511

CRITICAL CVSS 9.4 May 7, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the id parameter at /AddressBook/address_public_new.aspx. This allows attackers to execute arbitrary SQL commands on the databa...

CVE-2024-25514

CRITICAL CVSS 9.4 May 7, 2024

This SQL injection vulnerability in RuvarOA allows attackers to execute arbitrary SQL commands via the template_id parameter in the wf_template_child_field_list.aspx endpoint. This affects RuvarOA ver...

CVE-2024-25507

CRITICAL CVSS 9.4 May 7, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the email_attach_id parameter at /LHMail/AttachDown.aspx. This allows attackers to execute arbitrary SQL commands on the databa...

CVE-2024-25512

HIGH CVSS 8.1 May 7, 2024

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the attach_id parameter at /Bulletin/AttachDownLoad.aspx. This allows attackers to execute arbitrary SQL commands on the databa...