Show filters
5,502 Total Results
Displaying 261-270 of 5,502
Sort by:
Attacker Value
Unknown
CVE-2024-3938
Disclosure Date: July 25, 2024 (last updated February 26, 2025)
The "reset password" login page accepted an HTML injection via URL parameters.
This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E
This will result in a view along these lines:
* OWASP Top 10 - A03: Injection
* CVSS Score: 5.4
* AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
* https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
0
Attacker Value
Unknown
CVE-2024-41800
Disclosure Date: July 25, 2024 (last updated February 26, 2025)
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.
0
Attacker Value
Unknown
CVE-2024-6940
Disclosure Date: July 21, 2024 (last updated February 26, 2025)
A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271995. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-6932
Disclosure Date: July 20, 2024 (last updated February 26, 2025)
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271987.
0
Attacker Value
Unknown
CVE-2024-41600
Disclosure Date: July 19, 2024 (last updated August 23, 2024)
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
0
Attacker Value
Unknown
CVE-2024-39036
Disclosure Date: July 16, 2024 (last updated February 26, 2025)
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
0
Attacker Value
Unknown
CVE-2024-40322
Disclosure Date: July 16, 2024 (last updated February 26, 2025)
An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
0
Attacker Value
Unknown
CVE-2024-40552
Disclosure Date: July 12, 2024 (last updated July 13, 2024)
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
0
Attacker Value
Unknown
CVE-2024-40551
Disclosure Date: July 12, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2024-40550
Disclosure Date: July 12, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
0