Epesi is an open-source enterprise resource planning and customer relationship management platform with a concentrated vulnerability footprint centered on its core product. The recurring exposure reflects application-layer input-handling deficiencies, specifically cross-site scripting vulnerabilities that arise from improper neutralization of user input during web page generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epesi over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9621MEDIUM Cross-site scripting (XSS) vulnerability in modules/Base/Lang/Administrator/update_translation.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arb | Jun 14, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-6491MEDIUM Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, a | Mar 5, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-6490MEDIUM Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (cid, value, element, mo | Mar 5, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-6487MEDIUM Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (state, element, id, tab | Mar 5, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-9624MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted currency decimal-si | Jun 14, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-9623MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted country data. | Jun 14, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-9622MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted common data. | Jun 14, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6488MEDIUM Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (visible, tab, cid) pass | Mar 5, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-9331MEDIUM The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows | Jun 1, 2017 | 5.4 | 20 | NO | NO |
CVE-2017-9366MEDIUM Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary w | Jun 2, 2017 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epesi.
Media articles that mention a CVE ID that affects a product developed by Epesi — matched by CVE ID, not by vendor name.