Show filters
168 Total Results
Displaying 11-20 of 168
Sort by:
Attacker Value
Unknown
CVE-2024-5060
Disclosure Date: May 24, 2024 (last updated January 05, 2025)
The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-27307
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.
0
Attacker Value
Unknown
CVE-2024-24786
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
0
Attacker Value
Unknown
CVE-2023-5123
Disclosure Date: February 14, 2024 (last updated June 18, 2024)
The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of the dashboard-supplied path parameter, it was possible to include path traversal characters (../) in the path parameter and send requests to paths on the configured endpoint outside the configured sub-path.
This means that if the datasource was configured by an administrator to point at some sub-path of a domain (e.g. https://example.com/api/some_safe_api/ ), it was possible for an editor to create a dashboard referencing the datasource which issues queries containing path traversal characters, which would in turn cause the datasource to instead query arbitrary subpaths on the configured domain (e.g. https://exampl…
0
Attacker Value
Unknown
CVE-2022-48623
Disclosure Date: February 13, 2024 (last updated October 31, 2024)
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-21907
Disclosure Date: January 03, 2024 (last updated January 18, 2024)
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
0
Attacker Value
Unknown
CVE-2023-51074
Disclosure Date: December 27, 2023 (last updated January 12, 2024)
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
0
Attacker Value
Unknown
CVE-2023-6268
Disclosure Date: December 26, 2023 (last updated January 04, 2024)
The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-50472
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
0
Attacker Value
Unknown
CVE-2023-50471
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
0