Show filters
5,503 Total Results
Displaying 311-320 of 5,503
Sort by:
Attacker Value
Unknown

CVE-2024-36669

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
Attacker Value
Unknown

CVE-2024-36668

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-36667

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close
Attacker Value
Unknown

CVE-2024-36550

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close
Attacker Value
Unknown

CVE-2024-36549

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close
Attacker Value
Unknown

CVE-2024-36548

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-36547

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add
Attacker Value
Unknown

CVE-2024-36119

Disclosure Date: May 30, 2024 (last updated February 26, 2025)
Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic versions between 5.3.0 and 5.6.1. (This version range represents only one calendar week), 2. Using the `user:register_form` tag. 3. Using file-based user accounts. (Does not affect users stored in a database.), 4. Has users that have registered during that time period. (Existing users are not affected.). Additionally passwords are only visible to users that have access to read user yaml files, typically developers of the application itself. This issue has been patched in version 5.6.2, however any users registered during that time period and using the affected version range will still have the the `password_confirmation` value in their yaml files. We recommend that affected us…
0
Attacker Value
Unknown

CVE-2024-5521

Disclosure Date: May 30, 2024 (last updated February 26, 2025)
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of gallery editor or VFS resource manager will have the permission to upload images in the .svg format containing JavaScript code. The code will be executed the moment another user accesses the image.
0
Attacker Value
Unknown

CVE-2024-5520

Disclosure Date: May 30, 2024 (last updated February 26, 2025)
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
0