Show filters
809 Total Results
Displaying 211-220 of 809
Sort by:
Attacker Value
Unknown

CVE-2022-44959

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44957

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44956

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2022-44955

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.
Attacker Value
Unknown

CVE-2022-44954

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name field after clicking "Add".
Attacker Value
Unknown

CVE-2022-44953

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
Attacker Value
Unknown

CVE-2022-44291

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Attacker Value
Unknown

CVE-2022-44290

Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
Attacker Value
Unknown

CVE-2022-0421

Disclosure Date: November 21, 2022 (last updated February 24, 2025)
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
Attacker Value
Unknown

CVE-2022-43264

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.