Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2023-37636

Disclosure Date: October 23, 2023 (last updated October 30, 2023)
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
Attacker Value
Unknown

CVE-2023-39147

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
Attacker Value
Unknown

CVE-2023-33570

Disclosure Date: June 28, 2023 (last updated October 08, 2023)
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
Attacker Value
Unknown

CVE-2023-36287

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
Attacker Value
Unknown

CVE-2023-36284

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
Attacker Value
Unknown

CVE-2023-36289

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
Attacker Value
Unknown

CVE-2023-36288

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Attacker Value
Unknown

CVE-2023-2925

Disclosure Date: May 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-30256

Disclosure Date: May 11, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
Attacker Value
Unknown

CVE-2021-41924

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).