Agilefleet operates a fleet-management platform centered on its FleetCommander product line, which includes mobile kiosk interfaces for driver and vehicle tracking. The vulnerability profile concentrates on web-application input-handling and authentication weaknesses—including cross-site request forgery, SQL injection, cross-site scripting, and input-validation flaws—that are characteristic of internet-connected management and dispatch systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agilefleet over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4944HIGH Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file | Nov 18, 2012 | 10.0 | 30 | NO | NO |
CVE-2012-4945HIGH Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue. | Nov 18, 2012 | 7.5 | 23 | NO | NO |
CVE-2012-4941HIGH Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors | Nov 18, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-4943MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hijack the authentication of arbit | Nov 18, 2012 | 6.8 | 21 | NO | NO |
CVE-2012-4947MEDIUM Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive information via requests to uns | Nov 18, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-4946MEDIUM Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent attackers to obtain sensitive infor | Nov 18, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-4942MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via a | Nov 18, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agilefleet.
Media articles that mention a CVE ID that affects a product developed by Agilefleet — matched by CVE ID, not by vendor name.