Grupposcai's vulnerability profile centers on a narrowly scoped product portfolio anchored by RealGIMM, a web-based application where the recurring weakness classes—SQL injection, unrestricted file uploads, cross-site scripting, and XML entity expansion—reflect common input-handling and parsing gaps in web applications. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, underscoring the importance of timely patching for this focused product line. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grupposcai over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41637CRITICAL An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file | Aug 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-41642MEDIUM Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascrip | Aug 31, 2023 | 6.1 | 27 | NO | YES |
CVE-2023-41636CRITICAL A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a cra | Aug 31, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-41638HIGH An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file. | Aug 31, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-41640HIGH An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a cr | Aug 31, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-41635MEDIUM A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supply | Aug 31, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grupposcai.
Media articles that mention a CVE ID that affects a product developed by Grupposcai — matched by CVE ID, not by vendor name.