Show filters
72 Total Results
Displaying 11-20 of 72
Sort by:
Attacker Value
Unknown
CVE-2024-25634
Disclosure Date: February 19, 2024 (last updated December 19, 2024)
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue.
0
Attacker Value
Unknown
CVE-2024-25628
Disclosure Date: February 16, 2024 (last updated December 19, 2024)
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-25627
Disclosure Date: February 16, 2024 (last updated December 19, 2024)
Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads. As such, an attacker gaining administrative access to the alf.io application may be able to persist access by planting an XSS payload. This issue has been addressed in version 2.0-M4-2402. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6883
Disclosure Date: January 11, 2024 (last updated January 17, 2024)
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions, such as modifying the plugin's Facebook and Instagram access tokens and updating group IDs.
0
Attacker Value
Unknown
CVE-2023-50297
Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2023-49117
Disclosure Date: December 26, 2023 (last updated January 04, 2024)
PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2023-29484
Disclosure Date: October 16, 2023 (last updated February 25, 2025)
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
0
Attacker Value
Unknown
CVE-2015-10116
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.2.13 is able to address this issue. The identifier of the patch is 949a1ae7216216350458844f50a72f100b56d4e7. It is recommended to upgrade the affected component. The identifier VDB-230661 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-2260
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
0
Attacker Value
Unknown
CVE-2023-2259
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
0