Show filters
284 Total Results
Displaying 51-60 of 284
Sort by:
Attacker Value
Unknown

CVE-2024-22877

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript code inside the template or its variables, that will be executed in the context of the TheHive application when the HTML report is opened.
Attacker Value
Unknown

CVE-2024-22876

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicious HTML file with Javascript code that will be executed in the context of the The Hive application using a specific URL. The vulnerability can be used to coerce a victim account to perform specific actions on the application as helping an analyst becoming administrator.
Attacker Value
Unknown

CVE-2023-51071

Disclosure Date: January 13, 2024 (last updated January 20, 2024)
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.
Attacker Value
Unknown

CVE-2023-51070

Disclosure Date: January 13, 2024 (last updated January 20, 2024)
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.
Attacker Value
Unknown

CVE-2023-51068

Disclosure Date: January 13, 2024 (last updated January 19, 2024)
An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
Attacker Value
Unknown

CVE-2023-51067

Disclosure Date: January 13, 2024 (last updated January 19, 2024)
An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
Attacker Value
Unknown

CVE-2023-51066

Disclosure Date: January 13, 2024 (last updated January 20, 2024)
An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.
Attacker Value
Unknown

CVE-2023-51065

Disclosure Date: January 13, 2024 (last updated January 20, 2024)
Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.
Attacker Value
Unknown

CVE-2023-51064

Disclosure Date: January 13, 2024 (last updated January 20, 2024)
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.
Attacker Value
Unknown

CVE-2023-51063

Disclosure Date: January 13, 2024 (last updated January 19, 2024)
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.