Show filters
106 Total Results
Displaying 11-20 of 106
Sort by:
Attacker Value
Unknown

CVE-2022-45041

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
SQL Injection exits in xinhu < 2.5.0
Attacker Value
Unknown

CVE-2021-21751

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.
Attacker Value
Unknown

CVE-2021-21750

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.
Attacker Value
Unknown

CVE-2021-42329

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
0
Attacker Value
Unknown

CVE-2021-42331

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.
0
Attacker Value
Unknown

CVE-2021-42332

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parameters.
0
Attacker Value
Unknown

CVE-2021-42330

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.
0
Attacker Value
Unknown

CVE-2020-35388

Disclosure Date: December 26, 2020 (last updated November 28, 2024)
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
Attacker Value
Unknown

CVE-2020-8323

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2020-8321

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.