Vulnerabilities (CVE)

Filtered by vendor Itb-pim Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36643 1 Itb-pim 1 Tradepro 2025-04-24 N/A 7.5 HIGH
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.
CVE-2023-36645 1 Itb-pim 1 Tradepro 2025-04-24 N/A 9.1 CRITICAL
SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.
CVE-2023-36644 1 Itb-pim 1 Tradepro 2025-04-24 N/A 7.5 HIGH
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.