NA - CVE-2025-27447 - The web application is susceptible to...
The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s...
NA - CVE-2025-27448 - The web application is susceptible to...
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the...
NA - CVE-2025-27449 - The MEAC300-FNADE4 does not implement...
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
NA - CVE-2025-27450 - The Secure attribute is missing on multiple...
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request...
NA - CVE-2025-27451 - For failed login attempts, the application...
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to...
NA - CVE-2025-27452 - The configuration of the Apache httpd webserver...
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the...
NA - CVE-2025-27454 - The application is vulnerable to cross-site...
The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's...
NA - CVE-2025-27455 - The web application is vulnerable to...
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user...
NA - CVE-2025-27456 - The SMB server's login mechanism does not...
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.