Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[feehi/feehicms] FeehiCMS Cross Site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/19/2022

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36607
https://github.com/liufee/cms/issues/45
https://…

[feehi/feehicms] FeehiCMS vulnerable to Cross Site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/19/2022

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-20589
https://github.com/liufee/cms/issues/45
https://…

[@easy-team/easywebpack-cli] easywebpack-cli Path Traversal vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/16/2022

Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-24855
https://github.com/easy-team/easywebpack-cli/issues/…

[@easy-team/easywebpack-cli] easywebpack-cli Path Traversal vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/21/2022

Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-24855
https://github.com/easy-team/easywebpack-cli/issues/…

[django-photologue] django-photologue vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/22/2022

A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some unknown functionality of the file photologue/templates/photologue/photo_detail.html of the component Default Template Handler. The…

[org.wso2.carbon.registry:carbon-registry] WSO2 carbon-registry vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/16/2022

A vulnerability classified as problematic has been found in WSO2 carbon-registry before 4.8.7. This affects an unknown part of the component Request Parameter Handler. The manipulation of the argument parentPath/path/username/path/profile_menu leads to…

[collective.task] collective.task Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/27/2022

A vulnerability was found in collective.task up to 3.0.9. It has been classified as problematic. This affects the function renderCell/AssignedGroupColumn of the file src/collective/task/browser/table.py. The manipulation leads to cross site scripting. …

[org.wso2.carbon.registry:carbon-registry] WSO2 carbon-registry Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/21/2022

A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue is some unknown functionality of the file components/registry/org.wso2.carbon.registry.search.ui/src/main/resources/web/search/adva…

[roots/soil] Roots Soil plugin vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/16/202212/27/2022

A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.1.0. Affected is the function language_attributes of the file src/Modules/CleanUpModule.php. The manipulation of the argument language leads to cross site scri…

[helm.sh/helm/v3] Helm vulnerable to denial of service through schema file

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/15/202212/21/2022

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the chartutil package that can cause a segmentation violation. Applications that use functions from the chartutil package in the Helm SDK can have a Denial of Servi…

Posts navigation

Previous Posts 1 … 25 26 27 28 29 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close