Show filters
134 Total Results
Displaying 11-20 of 134
Sort by:
Attacker Value
Unknown

CVE-2024-46908

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
Attacker Value
Unknown

CVE-2024-46907

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
Attacker Value
Unknown

CVE-2024-46906

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
Attacker Value
Unknown

CVE-2024-46905

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
Attacker Value
Unknown

CVE-2024-53789

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Ritesh Sanap Advanced What should we write next about allows Stored XSS.This issue affects Advanced What should we write next about: from n/a through 1.0.3.
0
Attacker Value
Unknown

CVE-2024-51900

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard K Miller What Would Seth Godin Do allows Stored XSS.This issue affects What Would Seth Godin Do: from n/a through 2.1.1.
0
Attacker Value
Unknown

CVE-2024-10748

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Realm Database Handler. The manipulation of the argument defaultRealmKey leads to use of default cryptographic key. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-7763

Disclosure Date: October 24, 2024 (last updated October 31, 2024)
In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
Attacker Value
Unknown

CVE-2024-45607

Disclosure Date: September 12, 2024 (last updated September 19, 2024)
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Control, anyone using the post or verifyRequestSignature methods to handle messages is impacted. This vulnerability is fixed in 4.0.3.
Attacker Value
Unknown

CVE-2024-6672

Disclosure Date: August 29, 2024 (last updated September 05, 2024)
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.