Easyvista develops IT service management and help-desk solutions deployed in enterprise environments, with its vulnerability footprint concentrated in the Service Manager product line. The durable signal centers on application-layer input-handling and authentication weaknesses, including cross-site scripting, SQL injection, improper authentication, and insufficient rate-limiting on login attempts, which are characteristic of web-facing administrative interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easyvista over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38490HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | Jan 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-38492HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | Jan 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-38491HIGH An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corre | Jan 10, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-33231MEDIUM Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field. | Oct 20, 2022 | 5.4 | 23 | NO | NO |
CVE-2022-38489MEDIUM An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably. | Jan 10, 2023 | 5.4 | 20 | NO | NO |
CVE-2012-1256MEDIUM The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a | Feb 22, 2012 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easyvista.
Media articles that mention a CVE ID that affects a product developed by Easyvista — matched by CVE ID, not by vendor name.