Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via artlang parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the artlang parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1880
https://git…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to DOM cross-site scripting (XSS) because it fails to sanitize user input in the configuration privacy note URL parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[microweber/microweber] Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

microweber/microweber prior to 1.3.3 is vulnerable to stored cross-site scripting (XSS) via the X-Forwarded-For header. This was fixed in version 1.3.3.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1881
https://github.com/microweber/microweber…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to authentication bypass

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to authentication bypass by capture-relay that allows unlimited comments to be sent. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1886
https://github.com/thorsten/p…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to business logic errors

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 allows users with edit-only permissions to add and delete categories and add FAQs. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1887
https://github.com/thorsten/phpmyfaq/commit/4…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via FAQ News link parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the FAQ News link parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1757
https…

[uvdesk/community-skeleton] Uvdesk remote code execution vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 04/05/202304/12/2023

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
References

https://nvd.nist.gov/vuln/detail/CVE…

[markdown-pdf] markdown-pdf vulnerable to local file read via server side cross-site scripting (XSS)

  • Posted inHIGH
  • Posted byWpmaster
  • 04/05/202304/06/2023

markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
References

https://nvd.nist.gov/vuln/detail/CVE-2023…

[@sveltejs/kit] SvelteKit vulnerable to Cross-Site Request Forgery

  • Posted inHIGH
  • Posted byWpmaster
  • 04/05/202304/07/2023

Summary
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a +server.js file, containing endpoint handlers for different HTTP methods.
SvelteKit provides out-of-the-box cross-site request forgery (C…

[github.com/phachon/mm-wiki] Phachon mm-wiki Cross Site Request Forgery vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 04/05/202304/11/2023

Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-19278
https://github.com/phachon/mm-w…

Posts navigation

Previous Posts 1 2 3 4 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close