Overit's vulnerability footprint centers on its Geocall product, a narrowly scoped offering that encounters exposure across several categories of access and input-handling defects. The vendor's disclosures skew toward serious severity outcomes and recur through weakness classes including improper authentication, path traversal, cross-site scripting, and XML external entity injection—reflecting the authentication and web-layer input demands of a location-based service. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Overit over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5891CRITICAL An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web | Apr 1, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-22835MEDIUM An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to rea | Mar 10, 2022 | 6.5 | 28 | NO | NO |
CVE-2022-22834HIGH An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. At | Mar 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-5890HIGH An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative | Apr 1, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5889HIGH An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977. | Apr 1, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-5888MEDIUM Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977. | Apr 1, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Overit.
Media articles that mention a CVE ID that affects a product developed by Overit — matched by CVE ID, not by vendor name.