Show filters
538 Total Results
Displaying 191-200 of 538
Sort by:
Attacker Value
Unknown

CVE-2021-44478

Disclosure Date: March 08, 2022 (last updated February 23, 2025)
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary code and extract sensitive information by sending a specially crafted link to users with administrator privileges.
Attacker Value
Unknown

CVE-2020-18326

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Attacker Value
Unknown

CVE-2020-18325

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
Attacker Value
Unknown

CVE-2020-18324

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
Attacker Value
Unknown

CVE-2022-23043

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
Attacker Value
Unknown

CVE-2021-44567

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
Attacker Value
Unknown

CVE-2021-44566

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.
Attacker Value
Unknown

CVE-2021-44565

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.
Attacker Value
Unknown

CVE-2021-43724

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.
Attacker Value
Unknown

CVE-2021-25110

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.