Show filters
321 Total Results
Displaying 61-70 of 321
Sort by:
Attacker Value
Unknown
CVE-2023-33410
Disclosure Date: June 05, 2023 (last updated February 25, 2025)
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file.
0
Attacker Value
Unknown
CVE-2023-33409
Disclosure Date: June 05, 2023 (last updated February 25, 2025)
Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.
0
Attacker Value
Unknown
CVE-2023-33408
Disclosure Date: June 05, 2023 (last updated February 25, 2025)
Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the application's user input handling in the security_helper.php file.
0
Attacker Value
Unknown
CVE-2023-33955
Disclosure Date: May 30, 2023 (last updated February 25, 2025)
Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.
0
Attacker Value
Unknown
CVE-2023-23706
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
0
Attacker Value
Unknown
CVE-2023-0812
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
0
Attacker Value
Unknown
CVE-2023-1525
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2023-23710
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
0
Attacker Value
Unknown
CVE-2014-125094
Disclosure Date: April 06, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.140405 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-225001 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-1093
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
0