Show filters
333 Total Results
Displaying 151-160 of 333
Sort by:
Attacker Value
Unknown

CVE-2022-27330

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
Attacker Value
Unknown

CVE-2022-24864

Disclosure Date: April 20, 2022 (last updated February 23, 2025)
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the founders@originprotocol.com. If the email recipient is using an email program that is susceptible to XSS, then that email recipient will receive an email that may contain malicious XSS. Regardless if the email recipient’s mail program has vulnerabilities or not, the hacker can at the very least inject malicious HTML that modifies the body content of the email. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2022-1329

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
Attacker Value
Unknown

CVE-2022-27357

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-27346

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-26615

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
Attacker Value
Unknown

CVE-2022-27436

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
Attacker Value
Unknown

CVE-2022-27435

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
Attacker Value
Unknown

CVE-2022-1078

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.
Attacker Value
Unknown

CVE-2022-1075

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.