Floorsightsoftware develops a focused portfolio of enterprise management and analytics applications, including its Customer Portal and Insight products, that handle access-controlled business data. The observed vulnerability pattern centers on authorization-bypass weaknesses rooted in user-controlled keys, a recurring flaw class that reflects the access-control and session-management complexity in web-facing administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Floorsightsoftware over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45893HIGH An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer inform | Jan 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-45892HIGH An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information. | Jan 2, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Floorsightsoftware.
Media articles that mention a CVE ID that affects a product developed by Floorsightsoftware — matched by CVE ID, not by vendor name.