Smod maintains a focused product line centered on the smodbip application, where its vulnerability record reflects web application input-handling issues including cross-site request forgery and cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smod over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4837HIGH SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with admi | Oct 10, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-5378MEDIUM Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in version | Jan 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smod.
Media articles that mention a CVE ID that affects a product developed by Smod — matched by CVE ID, not by vendor name.