Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2023-31183
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.
0
Attacker Value
Unknown
CVE-2022-22794
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.
0
Attacker Value
Unknown
CVE-2022-22793
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.
0
Attacker Value
Unknown
CVE-2021-36720
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
0
Attacker Value
Unknown
CVE-2021-36719
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.
0
Attacker Value
Unknown
CVE-2020-8274
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
0
Attacker Value
Unknown
CVE-2020-8275
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
0
Attacker Value
Unknown
CVE-2018-6289
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
0
Attacker Value
Unknown
CVE-2018-6290
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
0