Polarisft maintains a narrowly scoped footprint centered on its Intellect Core Banking platform, a financial software product serving banking and financial-services deployments. The recurring vulnerability signal reflects application-layer input handling and session-management issues, including cross-site request forgery, cross-site scripting, SQL injection, and open-redirect flaws that are characteristic of web-facing financial applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polarisft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14931MEDIUM An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI. | Apr 30, 2019 | 6.1 | 30 | NO | YES |
CVE-2018-14874HIGH An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /refe | Apr 30, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-14930HIGH An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI. | Apr 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-14875MEDIUM An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, | Apr 30, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polarisft.
Media articles that mention a CVE ID that affects a product developed by Polarisft — matched by CVE ID, not by vendor name.