📦 Sentrifugo

by Sapplica

🔍 What is Sentrifugo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-29871

CRITICAL CVSS 9.8 Mar 21, 2024

This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL commands through the 'id' parameter in specific endpoints. Successful exploitation could lead to com...

CVE-2024-29873

CRITICAL CVSS 9.8 Mar 21, 2024

This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL queries through the 'bunitname' parameter in the business units report endpoint. Successful exploita...

CVE-2024-29875

CRITICAL CVSS 9.8 Mar 21, 2024

This is a critical SQL injection vulnerability in Sentrifugo 3.2 that allows remote attackers to execute arbitrary SQL queries through the 'sort_name' parameter. Successful exploitation could lead to ...

CVE-2024-29877

HIGH CVSS 7.1 Mar 21, 2024

This is a Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2 that allows attackers to inject malicious scripts via the 'expense_category_name' parameter in the expense categories edit page. Wh...

CVE-2024-29879

HIGH CVSS 7.1 Mar 21, 2024

This is a reflected Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2 that allows attackers to inject malicious scripts via the 'business_id' parameter. When exploited, it can steal user sess...