Show filters
639 Total Results
Displaying 41-50 of 639
Sort by:
Attacker Value
Unknown
CVE-2022-0951
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
0
Attacker Value
Unknown
CVE-2022-0950
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.
0
Attacker Value
Unknown
CVE-2022-0945
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
0
Attacker Value
Unknown
CVE-2022-24749
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or loaded outside of the IMG tag. The problem applies both to the files opened on the admin panel and shop pages. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. As a workaround, require a library that adds on-upload file sanitization and overwrite the service before writing the file to the filesystem. The GitHub Security Advisory contains more specific information about the workaround.
0
Attacker Value
Unknown
CVE-2022-0962
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
0
Attacker Value
Unknown
CVE-2022-0960
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
0
Attacker Value
Unknown
CVE-2021-42171
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
0
Attacker Value
Unknown
CVE-2022-24387
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
0
Attacker Value
Unknown
CVE-2022-0930
Disclosure Date: March 12, 2022 (last updated February 23, 2025)
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
0
Attacker Value
Unknown
CVE-2022-0921
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
0