Show filters
285 Total Results
Displaying 81-90 of 285
Sort by:
Attacker Value
Unknown
CVE-2023-3677
Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscribers or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2023-39291
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
0
Attacker Value
Unknown
CVE-2023-39290
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
0
Attacker Value
Unknown
CVE-2023-39289
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.
0
Attacker Value
Unknown
CVE-2023-39288
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
0
Attacker Value
Unknown
CVE-2023-39287
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
0
Attacker Value
Unknown
CVE-2023-39293
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
0
Attacker Value
Unknown
CVE-2023-39292
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
0
Attacker Value
Unknown
CVE-2023-32748
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
0
Attacker Value
Unknown
CVE-2022-46902
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. During the unzip operation, the code takes file paths from the ZIP archive and writes them to a Vocera temporary directory. Unfortunately, the code does not properly check if the file paths include directory traversal payloads that would escape the intended destination.
0