Show filters
538 Total Results
Displaying 191-200 of 538
Sort by:
Attacker Value
Unknown
CVE-2021-44478
Disclosure Date: March 08, 2022 (last updated February 23, 2025)
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary code and extract sensitive information by sending a specially crafted link to users with administrator privileges.
0
Attacker Value
Unknown
CVE-2020-18326
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
0
Attacker Value
Unknown
CVE-2020-18325
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
0
Attacker Value
Unknown
CVE-2020-18324
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
0
Attacker Value
Unknown
CVE-2022-23043
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
0
Attacker Value
Unknown
CVE-2021-44567
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
0
Attacker Value
Unknown
CVE-2021-44566
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramFunctions/MarkDownHTML.fnc.php.
0
Attacker Value
Unknown
CVE-2021-44565
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.
0
Attacker Value
Unknown
CVE-2021-43724
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.
0
Attacker Value
Unknown
CVE-2021-25110
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.
0