Show filters
93 Total Results
Displaying 71-80 of 93
Sort by:
Attacker Value
Unknown

CVE-2021-43397

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
Attacker Value
Unknown

CVE-2021-37254

Disclosure Date: October 28, 2021 (last updated November 28, 2024)
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
Attacker Value
Unknown

CVE-2021-24349

Disclosure Date: June 14, 2021 (last updated February 22, 2025)
This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.
Attacker Value
Unknown

CVE-2021-30140

Disclosure Date: April 06, 2021 (last updated February 22, 2025)
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.
Attacker Value
Unknown

CVE-2021-3183

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.
Attacker Value
Unknown

CVE-2020-29072

Disclosure Date: November 25, 2020 (last updated February 22, 2025)
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
Attacker Value
Unknown

CVE-2020-29071

Disclosure Date: November 25, 2020 (last updated February 22, 2025)
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.
Attacker Value
Unknown

CVE-2018-18276

Disclosure Date: April 26, 2019 (last updated November 27, 2024)
XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel.
0
Attacker Value
Unknown

CVE-2018-16462

Disclosure Date: October 30, 2018 (last updated November 27, 2024)
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
Attacker Value
Unknown

Insecure temporary file use in base-files

Disclosure Date: August 21, 2018 (last updated November 27, 2024)
The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.