📦 Workplace Suite

by Xerox

🔍 What is Workplace Suite?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-55926

HIGH CVSS 7.6 Jan 23, 2025

A vulnerability in Xerox Workplace Suite allows attackers to read, upload, and delete arbitrary files on the server by manipulating HTTP headers. This occurs due to improper validation of header input...

CVE-2024-55927

HIGH CVSS 7.6 Jan 23, 2025

This vulnerability in Xerox Workplace Suite allows attackers to predict or forge authentication tokens due to flawed token generation and hard-coded cryptographic keys. This enables unauthorized acces...

CVE-2024-55925

HIGH CVSS 7.5 Jan 23, 2025

This vulnerability allows attackers to bypass API host restrictions in Xerox Workplace Suite by forging Host headers. Attackers can access sensitive API endpoints that should be restricted to specific...

CVE-2024-55928

MEDIUM CVSS 6.5 Jan 23, 2025

Xerox Workplace Suite stores sensitive secrets like passwords and API keys in unencrypted plain text, making them accessible to attackers who can read local files or intercept network traffic. This af...

CVE-2024-55930

MEDIUM CVSS 6.7 Jan 23, 2025

Xerox Workplace Suite has insecure default folder permissions that allow unauthorized users to access, modify, or delete files within the application's directories. This affects organizations using vu...