Show filters
935 Total Results
Displaying 241-250 of 935
Sort by:
Attacker Value
Unknown
CVE-2023-6199
Disclosure Date: November 20, 2023 (last updated February 25, 2025)
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
0
Attacker Value
Unknown
CVE-2023-48240
Disclosure Date: November 20, 2023 (last updated February 25, 2025)
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for images from other domains and include all cookies that were sent in the original request to ensure that images with restricted view right can be compared. Starting in version 11.10.1 and prior to versions 14.10.15, 15.5.1, and 15.6, this allows an attacker to steal login and session cookies that allow impersonating the current user who views the diff. The attack can be triggered with an image that references the rendered diff, thus making it easy to trigger. Apart from stealing login cookies, this also allows server-side request forgery (the result of any successful request is returned in the image's source) and viewing protected content as once a resource is cached, it is returned for all users. As only succes…
0
Attacker Value
Unknown
CVE-2023-48204
Disclosure Date: November 16, 2023 (last updated February 25, 2025)
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
0
Attacker Value
Unknown
CVE-2023-6124
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
0
Attacker Value
Unknown
CVE-2023-46207
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
0
Attacker Value
Unknown
CVE-2023-41239
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.
0
Attacker Value
Unknown
CVE-2023-38515
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.
0
Attacker Value
Unknown
CVE-2023-37978
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11.
0
Attacker Value
Unknown
CVE-2023-34013
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best WordPress Poll Plugin: from n/a through 4.6.2.
0
Attacker Value
Unknown
CVE-2023-31219
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
0