Show filters
174 Total Results
Displaying 41-50 of 174
Sort by:
Attacker Value
Unknown
CVE-2022-2240
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
0
Attacker Value
Unknown
CVE-2022-2239
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2022-25803
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
0
Attacker Value
Unknown
CVE-2022-25802
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
0
Attacker Value
Unknown
CVE-2022-25801
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
0
Attacker Value
Unknown
CVE-2022-25800
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
0
Attacker Value
Unknown
CVE-2022-34815
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.
0
Attacker Value
Unknown
CVE-2022-34814
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.
0
Attacker Value
Unknown
CVE-2022-34782
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
0
Attacker Value
Unknown
CVE-2022-0654
Disclosure Date: February 23, 2022 (last updated February 23, 2025)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.
0