Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[liquidjs] liquidjs may leak properties of a prototype

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202201/03/2023

The package liquidjs before 10.0.0 is vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functional…

[jsonwebtoken] jsonwebtoken’s insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202201/06/2023

Overview
Versions <=8.5.1 of jsonwebtoken library can be misconfigured so that passing a poorly implemented key retrieval function (referring to the secretOrPublicKey argument from the readme link) will result in incorrect verification of tokens. Th…

[jsonwebtoken] jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202201/09/2023

Overview
In versions <=8.5.1 of jsonwebtoken library, lack of algorithm definition and a falsy secret or key in the jwt.verify() function can lead to signature validation bypass due to defaulting to the none algorithm for signature verification.
Am …

[jsonwebtoken] jsonwebtoken unrestricted key type could lead to legacy keys usage

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/23/2022

Overview
Versions <=8.5.1 of jsonwebtoken library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm.
Am I affected?
You are affected if you ar…

[rdiffweb] rdiffweb Open Redirect vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/30/2022

rdiffweb prior to version 2.5.4 has an Open Redirect vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4644
https://github.com/ikus060/rdiffweb/commit/5f861670ef8f38ca8eea52a98672d0e0fabb5368
https://huntr.dev/bounties/77e5f425-c764-…

[microweber/microweber] Microweber vulnerable to Stored Cross-Site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/27/2022

Microweber versions 1.3.1 and prior are vulnerable to stored Cross-site Scripting (XSS). A patch is available on the 1.4, dev, and laravel-sail branches.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4647
https://github.com/microweber/microwebe…

[rdiffweb] rdiffweb vulnerable to Cross-Site Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/30/2022

rdiffweb prior to version 2.5.4 is vulnerable to Cross-Site Request Forgery (CSRF).
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4646
https://github.com/ikus060/rdiffweb/commit/e6f0d8002129be90fe82fa3e3ea0a6942caba398
https://huntr.dev/bountie…

[net.mingsoft:ms-mcms] Mingsoft MCMS Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/23/2022

A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remote…

[collective.contact.widget] collective.contact.widget is vulnerable to cross-site scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/29/2022

collective.contact.widget is an add-on is part of the collective.contact.* suite. A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/cont…

[github.com/studygolang/studygolang] studygolang vulnerable to cross-site scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/30/2022

A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate the attack rem…

Posts navigation

Previous Posts 1 … 22 23 24 25 26 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close