Mind develops the iMind Server product, a web-based application whose vulnerability profile centers on application-layer input handling and access control, with observed weaknesses including direct-request vulnerabilities, improper formula element neutralization in CSV exports, and cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mind over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25398HIGH CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality. | Nov 5, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-24765HIGH InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-info | Oct 20, 2020 | 7.5 | 26 | NO | NO |
CVE-2020-25399HIGH Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat. | Nov 5, 2020 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mind.
Media articles that mention a CVE ID that affects a product developed by Mind — matched by CVE ID, not by vendor name.