Show filters
182 Total Results
Displaying 111-120 of 182
Sort by:
Attacker Value
Unknown

CVE-2021-22953

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
Attacker Value
Unknown

CVE-2021-22950

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
Attacker Value
Unknown

CVE-2021-25959

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
Attacker Value
Unknown

CVE-2021-36766

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.
Attacker Value
Unknown

CVE-2021-23399

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
Attacker Value
Unknown

CVE-2021-28833

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.
Attacker Value
Unknown

CVE-2021-28145

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
Attacker Value
Unknown

CVE-2021-28796

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.
Attacker Value
Unknown

CVE-2021-3122

Disclosure Date: February 07, 2021 (last updated February 22, 2025)
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."
Attacker Value
Unknown

CVE-2021-3111

Disclosure Date: January 08, 2021 (last updated February 22, 2025)
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.