Show filters
1,715 Total Results
Displaying 161-170 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2024-25646

Disclosure Date: April 09, 2024 (last updated September 28, 2024)
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.
0
Attacker Value
Unknown

CVE-2024-29879

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
Attacker Value
Unknown

CVE-2024-29878

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
Attacker Value
Unknown

CVE-2024-29877

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
Attacker Value
Unknown

CVE-2024-29876

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
Attacker Value
Unknown

CVE-2024-29875

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
Attacker Value
Unknown

CVE-2024-29874

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
Attacker Value
Unknown

CVE-2024-29873

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
Attacker Value
Unknown

CVE-2024-29872

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
Attacker Value
Unknown

CVE-2024-29871

Disclosure Date: March 21, 2024 (last updated January 25, 2025)
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.