Eic's vulnerability footprint centers on a niche e-document system product line, with a durable signal rooted in authentication bypass, sensitive information exposure, and SQL injection vulnerabilities—characteristic of web-facing application tiers handling document workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eic over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22860CRITICAL EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credentia | Mar 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-22859CRITICAL The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary com | Mar 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-11232CRITICAL EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_use | Jun 19, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11233HIGH EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the auth/main/asp/check_user_login_in | Jun 19, 2019 | 7.5 | 24 | NO | NO |
CVE-2021-34683MEDIUM An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact in | Jun 16, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eic.
Media articles that mention a CVE ID that affects a product developed by Eic — matched by CVE ID, not by vendor name.