Show filters
239 Total Results
Displaying 71-80 of 239
Sort by:
Attacker Value
Unknown

CVE-2024-41252

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.
Attacker Value
Unknown

CVE-2024-41251

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.
Attacker Value
Unknown

CVE-2024-41249

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.
Attacker Value
Unknown

CVE-2024-41248

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.
Attacker Value
Unknown

CVE-2024-41247

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.
Attacker Value
Unknown

CVE-2024-41246

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.
Attacker Value
Unknown

CVE-2024-3238

Disclosure Date: August 02, 2024 (last updated January 05, 2025)
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please not the CSRF was patched in 5.0.28, however, adequate directory traversal protection wasn't introduced until 5.0.30.
0
Attacker Value
Unknown

CVE-2024-2508

Disclosure Date: July 31, 2024 (last updated January 05, 2025)
The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up to, and including, 2.8.4.4. This makes it possible for unauthenticated attackers to add the '_mobmenu_icon' post meta to arbitrary posts with an arbitrary (but sanitized) value. NOTE: Version 2.8.4.4 contains a partial fix for this vulnerability.
0
Attacker Value
Unknown

CVE-2024-4096

Disclosure Date: July 30, 2024 (last updated July 30, 2024)
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown

CVE-2024-37120

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.