Show filters
898 Total Results
Displaying 51-60 of 898
Sort by:
Attacker Value
Unknown

CVE-2022-24742

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.
Attacker Value
Unknown

CVE-2021-41850

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.
Attacker Value
Unknown

CVE-2021-41849

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.
Attacker Value
Unknown

CVE-2021-32477

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
Attacker Value
Unknown

CVE-2021-32473

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected
Attacker Value
Unknown

CVE-2022-25512

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.
Attacker Value
Unknown

CVE-2022-26847

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
Attacker Value
Unknown

CVE-2022-25830

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log
Attacker Value
Unknown

CVE-2022-25829

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log
Attacker Value
Unknown

CVE-2022-25828

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log