Notrinos develops an enterprise resource planning application, Notrinos ERP, that handles sensitive business and personal data across financial and operational workflows. The vendor's vulnerability surface centers on web application input handling and data-access control, with recurrent issues spanning cross-site scripting, SQL injection, inadequate password policies, clickjacking-style framing attacks, and exposure of private personal information. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Notrinos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24788HIGH NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php. | Mar 23, 2023 | 8.8 | 32 | NO | YES |
CVE-2022-2927CRITICAL Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. | Aug 22, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-2921HIGH Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administ | Aug 21, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-2871MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7. | Aug 17, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-2965MEDIUM Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7. | Aug 23, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Notrinos.
Media articles that mention a CVE ID that affects a product developed by Notrinos — matched by CVE ID, not by vendor name.