Aceware's vulnerability footprint centers on its AceWeb Online Portal, a web-based application where the identified exposures cluster around input-handling and file-handling weaknesses including unrestricted file uploads, improper input validation, cross-site scripting, SQL injection, and external resource references. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aceware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24240CRITICAL ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp. | Jun 2, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-24239CRITICAL ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. | Jun 2, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-24581HIGH ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce | Jun 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-24241HIGH ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp. | Jun 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-24238MEDIUM ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp. | Jun 2, 2022 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aceware.
Media articles that mention a CVE ID that affects a product developed by Aceware — matched by CVE ID, not by vendor name.