Show filters
809 Total Results
Displaying 271-280 of 809
Sort by:
Attacker Value
Unknown
CVE-2021-29397
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.
0
Attacker Value
Unknown
CVE-2021-29396
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
0
Attacker Value
Unknown
CVE-2021-29395
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
0
Attacker Value
Unknown
CVE-2021-29394
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.
0
Attacker Value
Unknown
CVE-2021-29393
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
0
Attacker Value
Unknown
CVE-2022-23980
Disclosure Date: February 03, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'.
0
Attacker Value
Unknown
CVE-2021-24965
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
0
Attacker Value
Unknown
CVE-2021-24893
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
0
Attacker Value
Unknown
CVE-2021-36889
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
0
Attacker Value
Unknown
CVE-2021-41067
Disclosure Date: December 14, 2021 (last updated February 23, 2025)
An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that can cause an installation of malicious content.
0