Munkireport Project maintains a focused IT asset-inventory and reporting platform that operates within macOS enterprise environments, with vulnerabilities centered on its web-application layer. The recurring exposure pattern reflects common application-development weaknesses: cross-site scripting, SQL injection, and cross-site request forgery, which recur across the core Munkireport product and related components and speak to the demands of secure input handling and session management in web-facing inventory systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Munkireport Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15884HIGH A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /data | Jul 23, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-10190HIGH An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables | Mar 9, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-15882HIGH A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database. | Jul 23, 2020 | 8.1 | 20 | NO | NO |
CVE-2020-10192MEDIUM An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through the /report/broken_client endpoint. The payload will be exe | Mar 9, 2020 | 6.1 | 17 | NO | NO |
CVE-2020-15885MEDIUM A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment. | Jul 23, 2020 | 5.4 | 16 | NO | NO |
CVE-2020-10191MEDIUM An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /module/comment/save endpoint. The payload will be executed by | Mar 9, 2020 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Munkireport Project.
Media articles that mention a CVE ID that affects a product developed by Munkireport Project — matched by CVE ID, not by vendor name.