📦

portfolio

Vendor: extensis

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 4 Remote Access
Total CVEs 20 Total Indexed
Avg. EPSS 1.78% Exploit Prob.
Latest CVE CVE-2022-24255 Mar 01

Security Vulnerability Index

Page 1 / 2
8.8 CVSS

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

EPSS: 1.37%
8.8 CVSS

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

EPSS: 2.58%
8.8 CVSS

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

EPSS: 1.29%
8.8 CVSS

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

EPSS: 2.31%
8.8 CVSS
CVE-2022-24251
RCE Exploit Found

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

EPSS: 1.33%