Vulnerabilities (CVE)

Filtered by vendor Tsplus Subscribe
Filtered by product Tsplus Remote Work
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27132 1 Tsplus 1 Tsplus Remote Work 2023-12-10 N/A 9.8 CRITICAL
TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.
CVE-2023-27133 1 Tsplus 1 Tsplus Remote Work 2023-12-10 N/A 9.8 CRITICAL
TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product, not the TSplus Remote Work product.