Show filters
74 Total Results
Displaying 11-20 of 74
Sort by:
Attacker Value
Unknown
CVE-2024-23349
Disclosure Date: February 22, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-22393
Disclosure Date: February 22, 2024 (last updated February 14, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.
Users are recommended to upgrade to version [1.2.5], which fixes the issue.
0
Attacker Value
Unknown
CVE-2023-49619
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.2.0.
Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times.
Users are recommended to upgrade to version [1.2.1], which fixes the issue.
0
Attacker Value
Unknown
CVE-2023-4815
Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
0
Attacker Value
Unknown
CVE-2023-4127
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.
0
Attacker Value
Unknown
CVE-2023-4126
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
0
Attacker Value
Unknown
CVE-2023-4125
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
0
Attacker Value
Unknown
CVE-2023-4124
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
0
Attacker Value
Unknown
CVE-2021-4408
Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.8. This is due to missing or incorrect nonce validation on the update_answer() function. This makes it possible for unauthenticated attackers to update answers to questions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-2590
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.
0