Cyberpowersystems develops power management and UPS monitoring software, with a recurring vulnerability signal centered on its PowerPanel product and web-interface handling issues including cross-site request forgery and cross-site scripting. These weaknesses reflect input-validation and session-management gaps typical of management consoles; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyberpowersystems over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13071HIGH CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be explo | Jul 10, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-13070MEDIUM A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap | Jul 9, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberpowersystems.
Media articles that mention a CVE ID that affects a product developed by Cyberpowersystems — matched by CVE ID, not by vendor name.