Show filters
159 Total Results
Displaying 31-40 of 159
Sort by:
Attacker Value
Unknown

CVE-2023-22250

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2023-22249

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2023-22251

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Attacker Value
Unknown

CVE-2022-42218

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
Attacker Value
Unknown

CVE-2022-42143

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
Attacker Value
Unknown

CVE-2022-41536

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.
Attacker Value
Unknown

CVE-2022-41535

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.
Attacker Value
Unknown

CVE-2022-41532

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan.
Attacker Value
Unknown

CVE-2022-41530

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.
Attacker Value
Unknown

CVE-2022-35698

Disclosure Date: October 11, 2022 (last updated October 08, 2023)
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.