Midasolutions maintains the eFramework product, a narrowly scoped enterprise application whose vulnerability profile skews toward critical-severity outcomes and frequently acquires public exploit code. The recurring exposure centers on input-handling and access-control weaknesses—including cross-site scripting, OS command injection, SQL injection, path traversal, and improper authentication—that are characteristic of web application attack surfaces and reflect gaps in input sanitization and privilege enforcement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Midasolutions over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15920CRITICAL There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentic | Jul 24, 2020 | 9.8 | 94 | NO | YES |
CVE-2020-15922CRITICAL There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is re | Jul 24, 2020 | 9.8 | 73 | NO | YES |
CVE-2020-15921CRITICAL Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. | Jul 24, 2020 | 9.8 | 43 | NO | YES |
CVE-2020-15923HIGH Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. | Jul 24, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-15919MEDIUM A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. | Jul 24, 2020 | 6.1 | 22 | NO | NO |
CVE-2020-15924HIGH There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authenticat | Jul 24, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-15918MEDIUM Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. | Jul 24, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Midasolutions.
Media articles that mention a CVE ID that affects a product developed by Midasolutions — matched by CVE ID, not by vendor name.