Serpico Project maintains a specialized security-assessment documentation and reporting platform that, despite its narrow product scope, addresses a niche but important function in the vulnerability-management workflow. The vendor's vulnerability profile concentrates in its core Serpico product and recurs through web-application weakness classes including cross-site scripting, cross-site request forgery, improper authentication, and information-exposure flaws that are characteristic of internally deployed assessment tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serpico Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19854HIGH An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which | Jan 15, 2020 | 8.8 | 26 | NO | NO |
CVE-2019-19857MEDIUM An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using int | Jan 15, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-19859MEDIUM An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The Add Collaborator allows unlimited data via the author parameter, even if the data d | Jan 15, 2020 | 5.3 | 19 | NO | NO |
CVE-2019-19858MEDIUM An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter. | Jan 15, 2020 | 4.8 | 19 | NO | NO |
CVE-2019-19856MEDIUM An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter. | Jan 15, 2020 | 4.8 | 19 | NO | NO |
CVE-2019-19855MEDIUM An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter. | Jan 15, 2020 | 4.8 | 18 | NO | NO |
CVE-2020-12687MEDIUM An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user ac | May 7, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serpico Project.
Media articles that mention a CVE ID that affects a product developed by Serpico Project — matched by CVE ID, not by vendor name.