Workforceroi operates a focused workforce-management product portfolio centered on the Xpede platform, which occupies a specialized but prominent niche in human-capital and labor-optimization software. The vendor's disclosed vulnerabilities frequently acquire public exploit tooling, though the underlying weakness classes reflect generic input and data-handling concerns rather than product-specific architectural patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Workforceroi over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0486HIGH Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. | Aug 12, 2002 | 7.2 | 33 | NO | YES |
CVE-2002-0581HIGH WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp scri | Jun 18, 2002 | 7.5 | 21 | NO | NO |
CVE-2002-0579HIGH WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for | Jun 18, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-0580HIGH WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more e | Jun 18, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-0582MEDIUM WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by access | Jun 18, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-0583MEDIUM WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers t | Jun 18, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-0584MEDIUM WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is i | Jun 18, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-0487MEDIUM Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of o | Aug 12, 2002 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Workforceroi.
Media articles that mention a CVE ID that affects a product developed by Workforceroi — matched by CVE ID, not by vendor name.