Globalnorthstar's vulnerability footprint concentrates in its Northstar Club Management product, a niche administrative platform where vulnerabilities skew toward critical severity. The recurring weakness classes—path traversal, cleartext credential transmission, OS command injection, SQL injection, and authorization flaws—reflect common structural issues in administrative web applications and highlight particular risks in systems handling sensitive member and operational data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Globalnorthstar over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29396CRITICAL Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication. | Feb 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-29393CRITICAL Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitr | Feb 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-26959CRITICAL There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName p | Sep 16, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-29397HIGH Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept user | Feb 4, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-29395HIGH Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary file | Feb 4, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-29394MEDIUM Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any | Feb 4, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-29398MEDIUM Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to bro | Feb 4, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Globalnorthstar.
Media articles that mention a CVE ID that affects a product developed by Globalnorthstar — matched by CVE ID, not by vendor name.