Sitos maintains a narrowly scoped product portfolio centered on its SITOS Six platform, a web-based application whose vulnerability profile skews strongly toward critical-severity outcomes across a focused set of input-handling and privilege-management weakness classes. The recurring exposures—unrestricted file uploads, code injection, cross-site scripting, OS command injection, and improper privilege controls—reflect common risks in web applications handling user input and administrative access, and defenders should treat this vendor's advisories as high-priority despite the compact product footprint. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sitos over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15751CRITICAL An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This a | Oct 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-15748CRITICAL SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload | Oct 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-15746CRITICAL SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of | Oct 7, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-15747HIGH SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to insufficient checks on the server | Oct 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-15749MEDIUM SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an a | Oct 7, 2019 | 6.5 | 20 | NO | NO |
CVE-2019-15750MEDIUM A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | Oct 7, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sitos.
Media articles that mention a CVE ID that affects a product developed by Sitos — matched by CVE ID, not by vendor name.