Obm develops Open Business Management, a web-based business and project management platform where vulnerabilities have concentrated in application-layer input handling and access control, including cross-site scripting, path traversal, and SQL injection. This represents a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Obm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5141MEDIUM Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote authenticated users to include and execute | Aug 31, 2012 | 6.0 | 19 | NO | NO |
CVE-2011-5145MEDIUM Multiple SQL injection vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the | Aug 31, 2012 | 5.5 | 18 | NO | NO |
CVE-2011-5144MEDIUM Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to test.php, which calls the phpinfo function | Aug 31, 2012 | 5.0 | 18 | NO | NO |
CVE-2011-5143MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.3.20 and probably earlier allow remote attackers to inject arbitrary web script or HTML via | Aug 31, 2012 | 4.3 | 16 | NO | NO |
CVE-2011-5142MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers to inject arbitrary web script or HTML | Aug 31, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Obm.
Media articles that mention a CVE ID that affects a product developed by Obm — matched by CVE ID, not by vendor name.