Show filters
101 Total Results
Displaying 81-90 of 101
Sort by:
Attacker Value
Unknown
CVE-2017-18506
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
0
Attacker Value
Unknown
CVE-2019-7223
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.
0
Attacker Value
Unknown
CVE-2018-15756
Disclosure Date: October 18, 2018 (last updated November 08, 2023)
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.
0
Attacker Value
Unknown
CVE-2017-6213
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
0
Attacker Value
Unknown
CVE-2018-12255
Disclosure Date: July 03, 2018 (last updated November 26, 2024)
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
0
Attacker Value
Unknown
CVE-2017-18217
Disclosure Date: March 05, 2018 (last updated November 26, 2024)
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
0
Attacker Value
Unknown
CVE-2017-1000508
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
0
Attacker Value
Unknown
CVE-2017-1000466
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
0
Attacker Value
Unknown
CVE-2017-1000239
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.
0
Attacker Value
Unknown
CVE-2017-1000238
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.
0