Grandingteco's vulnerability footprint centers on its Utime Master product, a focused line of systems engineering or industrial control software, with disclosures clustered around authorization-bypass flaws arising from user-controlled cryptographic keys and cross-site scripting issues in web interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grandingteco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45393MEDIUM An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie. | Oct 13, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-45391MEDIUM A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute a | Oct 13, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grandingteco.
Media articles that mention a CVE ID that affects a product developed by Grandingteco — matched by CVE ID, not by vendor name.