Show filters
698 Total Results
Displaying 151-160 of 698
Sort by:
Attacker Value
Unknown

CVE-2022-44960

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
Attacker Value
Unknown

CVE-2022-44959

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44957

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44956

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44955

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.
Attacker Value
Unknown

CVE-2022-44954

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name field after clicking "Add".
Attacker Value
Unknown

CVE-2022-44953

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
Attacker Value
Unknown

CVE-2022-44291

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Attacker Value
Unknown

CVE-2022-44290

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
Attacker Value
Unknown

CVE-2022-39389

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs, and close out channels. Opening channels is prohibited, and also on chain transaction events will be undetected. This can cause loss of funds if a CSV expiry is researched during a breach attempt or a CLTV delta expires forgetting the funds in the HTLC. A patch is available in `lnd` version 0.15.4. Users are advised to upgrade. Users unable to upgrade may use the `lncli updatechanpolicy` RPC call to increase their CLTV value to a very high amount or increase their fee policies. This will prevent nodes from routing through your node, meaning that no pending HTLCs can be present.