Show filters
102 Total Results
Displaying 61-70 of 102
Sort by:
Attacker Value
Unknown
CVE-2022-30124
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
0
Attacker Value
Unknown
CVE-2022-2518
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. This is due to missing nonce validation on the stockist_settings_main() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2021-45026
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2021-45025
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
0
Attacker Value
Unknown
CVE-2021-45024
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
0
Attacker Value
Unknown
CVE-2020-36525
Disclosure Date: June 07, 2022 (last updated February 23, 2025)
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-21830
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
0
Attacker Value
Unknown
CVE-2022-0399
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2020-8291
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
0
Attacker Value
Unknown
CVE-2021-32832
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.
0