Show filters
1,715 Total Results
Displaying 161-170 of 1,715
Sort by:
Attacker Value
Unknown
CVE-2024-25646
Disclosure Date: April 09, 2024 (last updated September 28, 2024)
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-29879
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
0
Attacker Value
Unknown
CVE-2024-29878
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
0
Attacker Value
Unknown
CVE-2024-29877
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
0
Attacker Value
Unknown
CVE-2024-29876
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0
Attacker Value
Unknown
CVE-2024-29875
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0
Attacker Value
Unknown
CVE-2024-29874
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0
Attacker Value
Unknown
CVE-2024-29873
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0
Attacker Value
Unknown
CVE-2024-29872
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0
Attacker Value
Unknown
CVE-2024-29871
Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
0