Show filters
727 Total Results
Displaying 71-80 of 727
Sort by:
Attacker Value
Unknown

CVE-2023-50035

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
Attacker Value
Unknown

CVE-2023-48116

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.
Attacker Value
Unknown

CVE-2023-48115

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Attacker Value
Unknown

CVE-2023-48114

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.
Attacker Value
Unknown

CVE-2023-2487

Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
Attacker Value
Unknown

CVE-2023-5005

Disclosure Date: December 18, 2023 (last updated December 22, 2023)
The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-40656

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
Attacker Value
Unknown

CVE-2023-45066

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
Attacker Value
Unknown

CVE-2023-36677

Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
Attacker Value
Unknown

CVE-2023-46352

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.