Iblsoft develops Online Weather, a web-based aviation meteorological application where observed vulnerabilities center on web-application input and data-handling weaknesses: cleartext storage of sensitive information, code injection, and cross-site scripting. These patterns reflect the common risks in internet-facing data services that ingest and display user-supplied or third-party content without sufficient sanitization or encryption. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iblsoft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9406CRITICAL IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. | Feb 26, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-9405MEDIUM IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page. | Feb 26, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-9407MEDIUM IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie. | Feb 26, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iblsoft.
Media articles that mention a CVE ID that affects a product developed by Iblsoft — matched by CVE ID, not by vendor name.