Qsige presents a narrowly scoped vulnerability profile concentrated in a single product line, where the durable exposure centers on application-layer input handling and access control. The recurring weakness classes—SQL injection, cross-site scripting, authorization bypass, and unrestricted file upload—reflect common web-application security gaps and suggest that defenders should focus remediation on input validation, output encoding, and access-control enforcement. Live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qsige over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4100HIGH Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions. | Oct 3, 2023 | 8.2 | 27 | NO | NO |
CVE-2023-4103HIGH QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, D | Oct 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-4102HIGH QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary t | Oct 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-4098HIGH It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessa | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-4097HIGH The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application | Oct 3, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-4099MEDIUM The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it | Oct 3, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-4101MEDIUM The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessa | Oct 3, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qsige.
Media articles that mention a CVE ID that affects a product developed by Qsige — matched by CVE ID, not by vendor name.