Show filters
174 Total Results
Displaying 21-30 of 174
Sort by:
Attacker Value
Unknown

CVE-2023-49280

Disclosure Date: December 04, 2023 (last updated December 09, 2023)
XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and the changes are then exported in an XML file that anyone can download. So it's possible for an attacker to obtain password hash of users by performing an edit on the user profiles and then downloading the XML file that has been created. This is also true for any document that might contain password field and that a user can view. This vulnerability impacts all version of Change Request, but the impact depends on the rights that has been set on the wiki since it requires for the user to have the Change request right (allowed by default) and view rights on the page to target. This issue cannot be easily exploited in an automated way. The patch consists in denying to users the right of editing pages that contains a password field with change request. It means that already existing change request for those pages …
Attacker Value
Unknown

CVE-2023-45024

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
Attacker Value
Unknown

CVE-2023-41260

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Attacker Value
Unknown

CVE-2023-41259

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Attacker Value
Unknown

CVE-2023-45138

Disclosure Date: October 12, 2023 (last updated October 19, 2023)
Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when creating a new Change Request. This vulnerability is particularly critical as Change Request aims at being created by user without any particular rights. The vulnerability has been fixed in Change Request 1.9.2. It's possible to workaround the issue without upgrading by editing the document `ChangeRequest.Code.ChangeRequestSheet` and by performing the same change as in the fix commit.
Attacker Value
Unknown

CVE-2023-41937

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.
Attacker Value
Unknown

CVE-2023-33317

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Returns and Warranty Requests plugin <= 2.1.6 versions.
Attacker Value
Unknown

CVE-2023-36867

Disclosure Date: July 11, 2023 (last updated January 11, 2025)
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2020-26708

Disclosure Date: June 29, 2023 (last updated October 08, 2023)
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
Attacker Value
Unknown

CVE-2023-29423

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions.