Show filters
754 Total Results
Displaying 111-120 of 754
Sort by:
Attacker Value
Unknown
CVE-2023-49580
Disclosure Date: December 12, 2023 (last updated September 28, 2024)
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout configurations of the ABAP List Viewer and with this causing a mild impact on integrity and availability, e.g. also increasing the response times of the AS ABAP.
0
Attacker Value
Unknown
CVE-2023-47440
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
0
Attacker Value
Unknown
CVE-2023-49028
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file.
0
Attacker Value
Unknown
CVE-2023-49029
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.
0
Attacker Value
Unknown
CVE-2023-38885
Disclosure Date: November 20, 2023 (last updated December 01, 2023)
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
0
Attacker Value
Unknown
CVE-2023-38884
Disclosure Date: November 20, 2023 (last updated December 01, 2023)
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
0
Attacker Value
Unknown
CVE-2023-38883
Disclosure Date: November 20, 2023 (last updated December 01, 2023)
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.
0
Attacker Value
Unknown
CVE-2023-38882
Disclosure Date: November 20, 2023 (last updated December 01, 2023)
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php'
0
Attacker Value
Unknown
CVE-2023-38881
Disclosure Date: November 20, 2023 (last updated December 01, 2023)
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendar_id', 'school_date', 'month' or 'year' parameters in 'CalendarModal.php'.
0
Attacker Value
Unknown
CVE-2023-38880
Disclosure Date: November 20, 2023 (last updated November 30, 2023)
The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a format of "opensisBackup<date>.sql" (e.g. "opensisBackup07-20-2023.sql"), i.e. can easily be guessed. This file can be accessed by any unauthenticated actor and contains a dump of the whole database including password hashes.
0