Show filters
224 Total Results
Displaying 61-70 of 224
Sort by:
Attacker Value
Unknown
CVE-2023-43707
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "CatalogsPageDescriptionForm[1][name]
" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-43706
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "email_templates_key" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-43705
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "translation_value[1]" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-43704
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "title" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-43703
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-43702
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tracking_number" parameter,
potentially leading to unauthorized execution of scripts within a user's web browser.
0
Attacker Value
Unknown
CVE-2023-39022
Disclosure Date: July 28, 2023 (last updated October 08, 2023)
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
0
Attacker Value
Unknown
CVE-2023-38404
Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
0
Attacker Value
Unknown
CVE-2022-47165
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.
0
Attacker Value
Unknown
CVE-2023-32569
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
0