Show filters
200 Total Results
Displaying 11-20 of 200
Sort by:
Attacker Value
Unknown

CVE-2024-4637

Disclosure Date: June 04, 2024 (last updated January 28, 2025)
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-4581

Disclosure Date: June 04, 2024 (last updated January 28, 2025)
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation of this vulnerability requires an Administrator to give Slider Creation privileges to Author-level users.
Attacker Value
Unknown

CVE-2024-4092

Disclosure Date: May 02, 2024 (last updated February 04, 2025)
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.
Attacker Value
Unknown

CVE-2024-29844

Disclosure Date: April 15, 2024 (last updated September 26, 2024)
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.
0
Attacker Value
Unknown

CVE-2024-29843

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels
0
Attacker Value
Unknown

CVE-2024-29842

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user
0
Attacker Value
Unknown

CVE-2024-29841

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user
0
Attacker Value
Unknown

CVE-2024-29840

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user
0
Attacker Value
Unknown

CVE-2024-29839

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
0
Attacker Value
Unknown

CVE-2024-29838

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
0