Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/usememos/memos] usememos/memos Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202212/31/2022

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4849
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948
https://huntr.dev/bounti…

[github.com/usememos/memos] usememos/memos has Incorrectly Specified Destination in a Communication Channel

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/11/2023

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4847
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa39…

[github.com/usememos/memos] usememos/memos Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202212/31/2022

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4846
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948
https://huntr.dev/bounti…

[github.com/usememos/memos] usememos/memos Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/10/2023

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4845
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948
https://huntr.dev/bounties…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/10/2023

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos prior to 0.9.1.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4841
https://github.com/usememos/memos/commit/64e5c343c5f74b0abdf3ac0d21a6139daea58cf8
https://huntr.dev/bount…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/07/2023

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4840
https://github.com/usememos/memos/commit/64e5c343c5f74b0abdf3ac0d21a6139daea58cf8
https://huntr.dev/boun…

[github.com/usememos/memos] usememos/memos vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/07/2023

Cross-site Scripting (XSS) – Stored in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4839
https://github.com/usememos/memos/commit/64e5c343c5f74b0abdf3ac0d21a6139daea58cf8
https://huntr.dev/boun…

[github.com/usememos/memos] usememos/memos Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/07/2023

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos 0.9.0 and prior.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4844
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948
https://huntr.dev/bounti…

[github.com/usememos/memos] sememos/memos vulnerable to Improper Handling of Values

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/30/202201/18/2023

In usememos/memos 0.9.0 and prior, an attacker can post malicious content to another user’s memos page via POST request.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4851
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc…

[twitter-fetcher-js] Twitter-Post-Fetcher vulnerable to Use of Web Link to Untrusted Target with window.opener Access

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/10/2023

A vulnerability classified as problematic has been found in Twitter-Post-Fetcher up to 17.x. This affects an unknown part of the file js/twitterFetcher.js of the component Link Target Handler. The manipulation leads to use of web link to untrusted targ…

Posts navigation

Previous Posts 1 … 15 16 17 18 19 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close