Easyservice Billing Project develops a billing application whose vulnerability history centers on web-tier input-handling and request-validation weaknesses, including cross-site scripting, SQL injection, and cross-site request forgery. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easyservice Billing Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11444CRITICAL A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. | May 25, 2018 | 9.8 | 39 | NO | YES |
CVE-2018-11442HIGH A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation. | May 25, 2018 | 8.8 | 36 | NO | YES |
CVE-2018-11445HIGH A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role. | May 25, 2018 | 8.8 | 35 | NO | YES |
CVE-2018-11443MEDIUM The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | May 25, 2018 | 6.1 | 29 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easyservice Billing Project.
Media articles that mention a CVE ID that affects a product developed by Easyservice Billing Project — matched by CVE ID, not by vendor name.