Show filters
174 Total Results
Displaying 41-50 of 174
Sort by:
Attacker Value
Unknown

CVE-2022-2240

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
Attacker Value
Unknown

CVE-2022-2239

Disclosure Date: July 25, 2022 (last updated October 07, 2023)
The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2022-25803

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
Attacker Value
Unknown

CVE-2022-25802

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Attacker Value
Unknown

CVE-2022-25801

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Attacker Value
Unknown

CVE-2022-25800

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
Attacker Value
Unknown

CVE-2022-34815

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.
Attacker Value
Unknown

CVE-2022-34814

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.
Attacker Value
Unknown

CVE-2022-34782

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Attacker Value
Unknown

CVE-2022-0654

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.