Show filters
153 Total Results
Displaying 21-30 of 153
Sort by:
Attacker Value
Unknown
CVE-2024-6014
Disclosure Date: June 15, 2024 (last updated July 20, 2024)
A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268722 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-37301
Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
0
Attacker Value
Unknown
CVE-2024-34683
Disclosure Date: June 11, 2024 (last updated August 10, 2024)
An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to access, modify, or make the related information
unavailable in the victim’s browser.
0
Attacker Value
Unknown
CVE-2024-3749
Disclosure Date: May 15, 2024 (last updated May 15, 2024)
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
0
Attacker Value
Unknown
CVE-2024-3748
Disclosure Date: May 15, 2024 (last updated May 15, 2024)
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
0
Attacker Value
Unknown
CVE-2024-33002
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown
CVE-2024-1693
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.
0
Attacker Value
Unknown
CVE-2024-33923
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2024-32551
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71.
0
Attacker Value
Unknown
CVE-2024-29732
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.
0