Show filters
570 Total Results
Displaying 121-130 of 570
Sort by:
Attacker Value
Unknown
CVE-2022-39301
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code in "Personal Center" - "Profile Picture Upload" allowing theft of the user's personal information. This issue has been patched in 1.1.2. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2022-32176
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.
0
Attacker Value
Unknown
CVE-2022-42980
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
0
Attacker Value
Unknown
CVE-2022-32177
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.
0
Attacker Value
Unknown
CVE-2022-35857
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.
0
Attacker Value
Unknown
CVE-2022-1599
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
0
Attacker Value
Unknown
CVE-2021-37791
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?userCode=admin.
0
Attacker Value
Unknown
CVE-2022-23079
Disclosure Date: June 22, 2022 (last updated February 23, 2025)
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
0
Attacker Value
Unknown
CVE-2017-20066
Disclosure Date: June 20, 2022 (last updated February 23, 2025)
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-1814
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
0