Evasys is a survey and feedback management platform whose vulnerability profile concentrates in its core web application, with the durable signal centered on input-handling and access-control deficiencies such as cross-site scripting, SQL injection, and improper authorization. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evasys over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31433HIGH A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute SQL statements via the welche parameter. | May 2, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-31435HIGH Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 | May 2, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-31434MEDIUM The parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 do | May 2, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evasys.
Media articles that mention a CVE ID that affects a product developed by Evasys — matched by CVE ID, not by vendor name.