Show filters
727 Total Results
Displaying 71-80 of 727
Sort by:
Attacker Value
Unknown
CVE-2023-50035
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
0
Attacker Value
Unknown
CVE-2023-48116
Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.
0
Attacker Value
Unknown
CVE-2023-48115
Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
0
Attacker Value
Unknown
CVE-2023-48114
Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.
0
Attacker Value
Unknown
CVE-2023-2487
Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
0
Attacker Value
Unknown
CVE-2023-5005
Disclosure Date: December 18, 2023 (last updated December 22, 2023)
The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-40656
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
0
Attacker Value
Unknown
CVE-2023-45066
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
0
Attacker Value
Unknown
CVE-2023-36677
Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
0
Attacker Value
Unknown
CVE-2023-46352
Disclosure Date: November 02, 2023 (last updated November 10, 2023)
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.
0