Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2023-28731
Disclosure Date: March 30, 2023 (last updated November 08, 2023)
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.
This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
0
Attacker Value
Unknown
CVE-2021-24288
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.
0
Attacker Value
Unknown
CVE-2020-10934
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
0
Attacker Value
Unknown
CVE-2015-7338
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
0
Attacker Value
Unknown
CVE-2018-9107
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
0