Sesami's vulnerability profile centers on a specialized line of cash-management and logistics-optimization software, with a recurring signal in application-layer input handling and data-protection weaknesses. The exposure spans cross-site scripting, CSV-formula injection, cleartext transmission of sensitive information, improper authentication, and code-injection vulnerabilities that are characteristic of web-facing business applications handling financial data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sesami over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31300HIGH An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencr | Dec 29, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-31295HIGH CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile f | Dec 29, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-31294HIGH CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name | Dec 29, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-31299MEDIUM Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode | Dec 29, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-31301MEDIUM Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obta | Dec 29, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-31302MEDIUM Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field. | Dec 29, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-31296MEDIUM CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. | Dec 29, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-31292MEDIUM An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back | Dec 29, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-31298MEDIUM Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sens | Dec 29, 2023 | 4.8 | 16 | NO | NO |
CVE-2023-31293MEDIUM An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via | Dec 29, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sesami.
Media articles that mention a CVE ID that affects a product developed by Sesami — matched by CVE ID, not by vendor name.