Enferas

#950de 53,634
217.6CVSS total
Vulnerabilidades · 33
Média
27
Alta
2
Crítica
4
PT-2023-15702
6.1
2023-02-16
Mapos · Mapos · CVE-2022-48324
**Name of the Vulnerable Software and Affected Versions** Mapos version 4.39.0 **Description** Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos allow attackers to execute arbitrary code. The affected parameters include: `pesquisa`, `data`, `data2`, `nome`, `descricao`, `idDocumentos`, `id`, `senha`, `nomeCliente`, `contato`, `documento`, `telefone`, `celular`, `email`, `rua`, `numero`, `complemento`, `bairro`, `cidade`, `estado`, `cep`, `idClientes`, `id`, `tipo`, `forma pagamento`, `gateway de pagamento`, `excluir id`, `confirma id`, `cancela id`, `vencimento de`, `vencimento ate`, `cliente`, `tipo`, `status`, `valor desconto`, `desconto`, `periodo`, `per page`, `urlAtual`, `vencimento`, `recebimento`, `valor`, `recebido`, `formaPgto`, `desconto parc`, `entrada`, `qtdparcelas parc`, `valor parc`, `dia pgto`, `dia base pgto`, `comissao`, `descricao parc`, `cliente parc`, `observacoes parc`, `formaPgto parc`, `tipo parc`, `pagamento`, `pago`, `valor desconto editar`, `descricao`, `fornecedor`, `observacoes`, `id`, `refGarantia`, `textoGarantia`, `idGarantias`, `email`, and `senha` in various files such as application/controllers/Arquivos.php, application/controllers/Clientes.php, application/controllers/Cobrancas.php, application/controllers/Financeiro.php, application/controllers/Garantias.php, and application/controllers/Login.php. **Recommendations** As a temporary workaround, consider disabling the affected parameters until a patch is available. Restrict access to the vulnerable files to minimize the risk of exploitation. Avoid using the affected parameters in the respective API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-15705
6.1
2023-02-16
Mapos · Mapos · CVE-2022-48327
**Name of the Vulnerable Software and Affected Versions** Mapos version 4.39.0 **Description** Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos allow attackers to execute arbitrary code. The affected parameters include: `dataInicial`, `dataFinal`, `tipocliente`, `format`, `precoInicial`, `precoFinal`, `estoqueInicial`, `estoqueFinal`, `de id`, `ate id`, `clientes id`, `origem`, `cliente`, `responsavel`, `status`, `tipo`, `situacao` in file application/controllers/Relatorios.php, `preco`, `nome`, `descricao`, `idServicos`, `id` in file application/controllers/Servicos.php, `senha`, `permissoes id`, `idUsuarios`, `situacao`, `nome`, `rg`, `cpf`, `cep`, `rua`, `numero`, `bairro`, `cidade`, `estado`, `email`, `telefone`, `celular` in file application/controllers/Usuarios.php, `dataVenda`, `observacoes`, `observacoes cliente`, `clientes id`, `usuarios id`, `idVendas`, `id`, `idVendasProduto`, `preco`, `quantidade`, `idProduto`, `produto`, `desconto`, `tipoDesconto`, `resultado`, `vendas id`, `vencimento`, `recebimento`, `valor`, `recebido`, `formaPgto`, `tipo` in file application/controllers/Vendas.php, `situacao`, `periodo`, `vencimento de`, `vencimento ate`, `tipo`, `status`, `cliente` in file application/views/financeiro/lancamentos.php, `year` in file application/views/mapos/painel.php, `pesquisa` in file application/views/os/os.php, `etiquetaCode` in file application/views/relatorios/imprimir/imprimirEtiquetas.php. **Recommendations** As a temporary workaround, consider disabling the affected parameters until a patch is available. Restrict access to the vulnerable files to minimize the risk of exploitation. Avoid using the affected parameters in the respective files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-15703
6.1
2023-02-16
Mapos · Mapos · CVE-2022-48325
**Name of the Vulnerable Software and Affected Versions** Mapos version 4.39.0 **Description** Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos allow attackers to execute arbitrary code. The affected parameters include: `year`, `oldSenha`, `novaSenha`, `termo`, `nome`, `cnpj`, `ie`, `cep`, `logradouro`, `numero`, `bairro`, `cidade`, `uf`, `telefone`, `email`, `id`, `app name`, `per page`, `app theme`, `os notification`, `email automatico`, `control estoque`, `notifica whats`, `control baixa`, `control editos`, `control edit vendas`, `control datatable`, `pix key`, `os status list`, `control 2vias`, `status`, `start`, `end` in file application/controllers/Mapos.php, as well as `token`, `senha`, `email`, `nomeCliente`, `documento`, `telefone`, `celular`, `rua`, `numero`, `complemento`, `bairro`, `cidade`, `estado`, `cep`, `idClientes`, `descricaoProduto`, `defeito` in file application/controllers/Mine.php, and `pesquisa`, `status`, `data`, `data2`, `dataInicial`, `dataFinal`, `termoGarantia`, `garantias id`, `clientes id`, `usuarios id`, `idOs`, `garantia`, `descricaoProduto`, `defeito`, `observacoes`, `laudoTecnico`, `id`, `preco`, `quantidade`, `idProduto`, `idOsProduto`, `produto`, `idServico`, `idOsServico`, `desconto`, `tipoDesconto`, `resultado`, `vencimento`, `recebimento`, `os id`, `valor`, `recebido`, `formaPgto`, `tipo`, `anotacao`, `idAnotacao` in file application/controllers/Os.php. **Recommendations** As a temporary workaround, consider disabling the affected parameters until a patch is available. Restrict access to the vulnerable files application/controllers/Mapos.php, application/controllers/Mine.php, and application/controllers/Os.php to minimize the risk of exploitation. Avoid using the affected parameters in the respective API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.