Xinheinformation's vulnerability footprint centers on its teaching platform system, with observed weakness classes concentrated in authorization and access-control issues, including improper authorization, missing authorization checks, and cross-site scripting in web-facing components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xinheinformation over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42330HIGH The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other use | Oct 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-42331MEDIUM The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other user | Oct 15, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42329MEDIUM The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote att | Oct 15, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42332MEDIUM The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other user | Oct 15, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xinheinformation.
Media articles that mention a CVE ID that affects a product developed by Xinheinformation — matched by CVE ID, not by vendor name.