Smeup maintains an enterprise resource planning platform where the observed vulnerability exposure clusters around information-disclosure and input-handling defects, including cleartext storage of sensitive data, path traversal, OS command injection, and unrestricted file uploads. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smeup over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26759HIGH Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component. | Feb 27, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-26762HIGH Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability. | Feb 27, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-26760HIGH Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext cred | Feb 27, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-26758HIGH Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService. | Feb 27, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smeup.
Media articles that mention a CVE ID that affects a product developed by Smeup — matched by CVE ID, not by vendor name.