Sysjust develops a focused suite of web-based administrative and management applications, with vulnerabilities concentrating in products such as CTS Web and its Syuan-Gu-Da-Shin platform. The recurring weakness classes—improper authentication, cross-site scripting, SQL injection, and server-side request forgery—reflect common input-handling and access-control vulnerabilities endemic to web application development. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sysjust over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-3937HIGH SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database. | Feb 4, 2020 | 7.5 | 24 | NO | NO |
CVE-2021-32542MEDIUM The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows unauthenticated attackers can remotely perform reflected XSS a | May 28, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-32543MEDIUM The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and tr | May 28, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-32541MEDIUM The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of | May 28, 2021 | 5.3 | 19 | NO | NO |
CVE-2020-3938HIGH SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of th | Feb 4, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-3939MEDIUM SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal information may be leaked to attackers via the vulnerability. | Feb 4, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sysjust.
Media articles that mention a CVE ID that affects a product developed by Sysjust — matched by CVE ID, not by vendor name.