Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2023-37636
Disclosure Date: October 23, 2023 (last updated October 30, 2023)
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
0
Attacker Value
Unknown
CVE-2023-39147
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
0
Attacker Value
Unknown
CVE-2023-33570
Disclosure Date: June 28, 2023 (last updated October 08, 2023)
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
0
Attacker Value
Unknown
CVE-2023-36287
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
0
Attacker Value
Unknown
CVE-2023-36284
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
0
Attacker Value
Unknown
CVE-2023-36289
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
0
Attacker Value
Unknown
CVE-2023-36288
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
0
Attacker Value
Unknown
CVE-2023-2925
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-30256
Disclosure Date: May 11, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
0
Attacker Value
Unknown
CVE-2021-41924
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
0