Journyx develops a time and expense tracking application characterized by a vulnerability pattern centered on code-injection and input-handling weaknesses, including code injection, eval injection, cross-site scripting, and improper directive neutralization in dynamically evaluated contexts. These recurring weakness classes reflect the application's reliance on dynamic code evaluation and user-supplied input in web-facing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Journyx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6893HIGH The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform | Aug 8, 2024 | 7.5 | 50 | NO | YES |
CVE-2024-6892MEDIUM Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application. | Aug 8, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-6891HIGH Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. | Aug 8, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-6890HIGH Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and c | Aug 7, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Journyx.
Media articles that mention a CVE ID that affects a product developed by Journyx — matched by CVE ID, not by vendor name.