Dsk maintains a focused application portfolio centered on DskNet, a web-facing platform where observed vulnerabilities cluster around input-handling and authentication weaknesses including SQL injection, cross-site scripting, excessive authentication attempts, and dangerous file uploads. Live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dsk over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24688HIGH An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP | Jul 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-24690HIGH An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive | Jul 18, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-24691HIGH An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information v | Jul 18, 2022 | 7.1 | 23 | NO | NO |
CVE-2022-24692MEDIUM An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu | Jul 18, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-24689MEDIUM An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal | Jul 18, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dsk.
Media articles that mention a CVE ID that affects a product developed by Dsk — matched by CVE ID, not by vendor name.