Show filters
809 Total Results
Displaying 271-280 of 809
Sort by:
Attacker Value
Unknown

CVE-2021-29397

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.
Attacker Value
Unknown

CVE-2021-29396

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
Attacker Value
Unknown

CVE-2021-29395

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
Attacker Value
Unknown

CVE-2021-29394

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.
Attacker Value
Unknown

CVE-2021-29393

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
Attacker Value
Unknown

CVE-2022-23980

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'.
Attacker Value
Unknown

CVE-2021-24965

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
Attacker Value
Unknown

CVE-2021-24893

Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
Attacker Value
Unknown

CVE-2021-36889

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
Attacker Value
Unknown

CVE-2021-41067

Disclosure Date: December 14, 2021 (last updated February 23, 2025)
An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that can cause an installation of malicious content.