Show filters
294 Total Results
Displaying 111-120 of 294
Sort by:
Attacker Value
Unknown

CVE-2023-2579

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-2842

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
Attacker Value
Unknown

CVE-2023-30197

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.
Attacker Value
Unknown

CVE-2023-1806

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
Attacker Value
Unknown

CVE-2023-1363

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222870 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1351

Disclosure Date: March 11, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222849 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1179

Disclosure Date: March 05, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222330 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1131

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222106 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1130

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222105 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-24234

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.