Filtered by vendor Heimavista Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-2412 1 Heimavista 2 Epage, Rpage 2024-10-14 5.3 Medium
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
CVE-2022-39053 1 Heimavista 1 Dark Horse Rpage 2024-09-16 6.1 Medium
Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.