Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/usememos/memos] usememos/memos vulnerable Improper Restriction of Excessive Authentication Attempts

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

In usememos/memos 0.9.0 and prior, an attacker can delete other users’ posts via post id, which can be done via brute force.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4797
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170d…

[github.com/usememos/memos] usememos/memos Improper Authentication vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to Improper Authentication.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4799
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/c5d70f9d-b7…

[github.com/usememos/memos] usememos/memos vulnerable to Improper Verification of Source of a Communication Channel

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202212/31/2022

usememos/memos 0.9.0 and prior is vulnerable to Improper Verification of Source of a Communication Channel.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4800
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
htt…

[github.com/usememos/memos] usememos/memos has Insufficient Granularity of Access Control

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202212/31/2022

usememos/memos 0.9.0 and prior allows an attacker to archive any user’s public or private post.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4801
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.d…

[github.com/usememos/memos] usememos/memos vulnerable to Improper Authorization

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to Improper Authorization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4802
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/d47d4a94-92e…

[github.com/usememos/memos] usememos/memos Improper Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to Improper Authorization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4804
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/4ee48a1e-633…

[github.com/usememos/memos] usememos/memos Improper Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/29/202201/11/2023

usememos/memos 0.9.0 and prior is vulnerable to Improper Authorization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4798
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/e12eed25-1a8…

[harvesthq/chosen] Harvest Chosen vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202201/10/2023

A vulnerability, which was classified as problematic, has been found in Harvest Chosen up to 1.8.6. Affected by this issue is the function AbstractChosen of the file coffee/lib/abstract-chosen.coffee. The manipulation of the argument group_label leads …

[node-json2html] Json2html vulnerable to cross-site scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/29/2022

Json2html is a client side javascript HTML templating library with wrappers for both jQuery and Node.js. A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file jso…

[github.com/RobotsAndPencils/go-saml] go-saml’s XML Digital Signatures use SHA-1

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/28/202212/31/2022

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36563
…

Posts navigation

Previous Posts 1 … 17 18 19 20 21 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close