Arialsoftware's vulnerability footprint is concentrated in its Campaign Enterprise product, a specialized application where disclosures cluster around access-control and credential-management weaknesses including improper authentication, incorrect authorization, SQL injection, and insufficiently protected credentials. These recurrent patterns reflect the authentication and data-access demands of enterprise campaign management software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arialsoftware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3824HIGH In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization. | Jan 10, 2020 | 7.5 | 24 | NO | NO |
CVE-2012-3823HIGH Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. | Jan 10, 2020 | 7.5 | 24 | NO | NO |
CVE-2012-3822HIGH Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials. | Jan 10, 2020 | 7.5 | 24 | NO | NO |
CVE-2012-3820HIGH Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) | Aug 14, 2014 | 7.5 | 24 | NO | NO |
CVE-2012-3821MEDIUM A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber fiel | Jan 10, 2020 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arialsoftware.
Media articles that mention a CVE ID that affects a product developed by Arialsoftware — matched by CVE ID, not by vendor name.