Sandline's vulnerability profile concentrates in a narrowly scoped product line, with the recurring focus on its CentralEyezer application and web-input handling issues such as cross-site scripting and unrestricted file uploads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sandline over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12271CRITICAL Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the ser | Nov 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-12299MEDIUM Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section. | Nov 18, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-12311MEDIUM Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to do | Nov 18, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sandline.
Media articles that mention a CVE ID that affects a product developed by Sandline — matched by CVE ID, not by vendor name.