Echobh's modest vulnerability footprint centers on the Sharecare product and is characterized by application-layer input-handling and access-control weaknesses, including argument injection, SQL injection, missing authentication, and missing authorization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Echobh over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36124CRITICAL An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability | Jul 13, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-33578CRITICAL Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypa | Jul 13, 2021 | 9.8 | 28 | NO | NO |
CVE-2021-36122HIGH An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability w | Jul 13, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-36121HIGH An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via t | Jul 13, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-36123MEDIUM An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing | Jul 13, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Echobh.
Media articles that mention a CVE ID that affects a product developed by Echobh — matched by CVE ID, not by vendor name.