Ordat's vulnerability footprint is narrow, centered on its ERP product line, with the durable signal anchored in application-layer input-handling weaknesses such as cross-site scripting and SQL injection, alongside information-disclosure issues stemming from observable response discrepancies. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ordat over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34334HIGH ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function. | Sep 12, 2024 | 7.5 | 26 | NO | NO |
CVE-2024-34335MEDIUM ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page. | Sep 12, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-34336MEDIUM User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the f | Sep 12, 2024 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ordat.
Media articles that mention a CVE ID that affects a product developed by Ordat — matched by CVE ID, not by vendor name.