Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2023-31183

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.
Attacker Value
Unknown

CVE-2022-22794

Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.
Attacker Value
Unknown

CVE-2022-22793

Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.
Attacker Value
Unknown

CVE-2021-36720

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
Attacker Value
Unknown

CVE-2021-36719

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.
Attacker Value
Unknown

CVE-2020-8274

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
Attacker Value
Unknown

CVE-2020-8275

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
Attacker Value
Unknown

CVE-2018-6289

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown

CVE-2018-6290

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
0