Autore: Angelo Barbosa

CVE-2025-1643 | Benner ModernaNet up to 1.1.0 SG_AlterarSenha cross-site request forgery

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file /DadosPessoais/SG_AlterarSenha. The manipulation leads to cross-site request forgery. The identification of this vulnerability is CVE-2025-1643. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-1642 | Benner ModernaNet up to 1.1.0 GetImageMedico?fooId=1 fooId resource injection

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the argument fooId leads to improper control of resource identifiers. This vulnerability was named CVE-2025-1642. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-1641 | Benner ModernaNet up to 1.1.0 sql injection

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been classified as critical. This affects an unknown part of the file /AGE0000700/GetHorariosDoDia?idespec=0&idproced=1103&data=2025-02-25+19%3A25&agserv=0&convenio=1&localatend=1&idplano=5&pesfis=01&idprofissional=0&target=.horarios–dia–d0&_=1739371223797. The manipulation leads to sql injection. This vulnerability is uniquely identified as CVE-2025-1641. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-1640 | Benner ModernaNet up to 1.1.0 sql injection

A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /Home/JS_CarregaCombo?formName=DADOS_PESSOAIS_PLANO&additionalCondition=&insideParameters=&elementToReturn=DADOS_PESSOAIS_PLANO&ordenarPelaDescricao=true&direcaoOrdenacao=asc&_=1739290047295. The manipulation leads to sql injection. This vulnerability is handled as CVE-2025-1640. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-26803 | Phusion Passenger up to 6.0.25 HTTP Parser uninitialized resource

A vulnerability has been found in Phusion Passenger up to 6.0.25 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP Parser. The manipulation leads to uninitialized resource. This vulnerability is known as CVE-2025-26803. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più