Show filters
267 Total Results
Displaying 81-90 of 267
Sort by:
Attacker Value
Unknown
CVE-2023-48068
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
0
Attacker Value
Unknown
CVE-2023-36465
Disclosure Date: October 06, 2023 (last updated October 12, 2023)
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
0
Attacker Value
Unknown
CVE-2023-5301
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.
0
Attacker Value
Unknown
CVE-2023-43226
Disclosure Date: September 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
0
Attacker Value
Unknown
CVE-2023-5022
Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.
0
Attacker Value
Unknown
CVE-2023-40784
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
0
Attacker Value
Unknown
CVE-2023-4747
Disclosure Date: September 04, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238636.
0
Attacker Value
Unknown
CVE-2023-41049
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
0
Attacker Value
Unknown
CVE-2023-40877
Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
0
Attacker Value
Unknown
CVE-2023-40876
Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
0