Steelcase's vulnerability footprint centers on its RoomWizard meeting-space management and scheduling products, which operate at the intersection of web interfaces and embedded firmware. The recurring exposure involves information-disclosure, cross-site scripting, and server-side request forgery weaknesses typical of networked workplace-infrastructure applications where authentication and input handling are critical. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Steelcase over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7055HIGH GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter. | Feb 15, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-7057MEDIUM RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter. | Feb 15, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-7056MEDIUM RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action. | Feb 15, 2018 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Steelcase.
Media articles that mention a CVE ID that affects a product developed by Steelcase — matched by CVE ID, not by vendor name.