Show filters
93 Total Results
Displaying 11-20 of 93
Sort by:
Attacker Value
Unknown
CVE-2024-7605
Disclosure Date: September 05, 2024 (last updated September 13, 2024)
The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions up to, and including, 1.1.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to update plugin options, potentially disrupting the service.
0
Attacker Value
Unknown
CVE-2024-6883
Disclosure Date: August 21, 2024 (last updated August 21, 2024)
The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up to, and including, 5.0.22.decaf. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify some of the plugin settings.
0
Attacker Value
Unknown
CVE-2024-6687
Disclosure Date: August 01, 2024 (last updated January 05, 2025)
The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names, phone numbers, physical addresses, and email addresses
0
Attacker Value
Unknown
CVE-2024-37488
Disclosure Date: July 21, 2024 (last updated September 07, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HelloAsso allows Stored XSS.This issue affects HelloAsso: from n/a through 1.1.9.
0
Attacker Value
Unknown
CVE-2024-4604
Disclosure Date: June 26, 2024 (last updated January 05, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.
0
Attacker Value
Unknown
CVE-2024-4228
Disclosure Date: June 26, 2024 (last updated January 05, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability in Magarsus Consultancy SSO (Single Sign On) allows SQL Injection.This issue affects SSO (Single Sign On): from 1.0 before 1.1.
0
Attacker Value
Unknown
CVE-2023-27437
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.
0
Attacker Value
Unknown
CVE-2023-6544
Disclosure Date: April 25, 2024 (last updated April 26, 2024)
A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.
0
Attacker Value
Unknown
CVE-2023-6484
Disclosure Date: April 25, 2024 (last updated June 12, 2024)
A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
0
Attacker Value
Unknown
CVE-2023-3597
Disclosure Date: April 25, 2024 (last updated August 08, 2024)
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.
0