Show filters
744 Total Results
Displaying 101-110 of 744
Sort by:
Attacker Value
Unknown
CVE-2024-28191
Disclosure Date: April 09, 2024 (last updated January 18, 2025)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, do not output user data from frontend forms next to each other, always separate them by at least one character.
0
Attacker Value
Unknown
CVE-2024-28190
Disclosure Date: April 09, 2024 (last updated January 17, 2025)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, remove upload fields from frontend forms and disable uploads for untrusted back end users.
0
Attacker Value
Unknown
CVE-2023-45771
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: from n/a through 1.6.8.
0
Attacker Value
Unknown
CVE-2024-24770
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by calling the API routes `/recover/lost` and `/2fa/lost`. These routes send emails to users if they have lost their password or MFA token. This issue has been addressed in commit `aecfd6d0e` and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-24562
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
0
Attacker Value
Unknown
CVE-2024-23823
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server. The impact is limited because v6 does not use session cookies. This issue has been addressed in commit `70bb4e1d8` and is expected to ship in subsequent releases. Users are advised to upgrade as soon as a new release is available. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-26288
Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
0
Attacker Value
Unknown
CVE-2024-26005
Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.
0
Attacker Value
Unknown
CVE-2024-26004
Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
0
Attacker Value
Unknown
CVE-2024-26003
Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.
0