Show filters
318 Total Results
Displaying 81-90 of 318
Sort by:
Attacker Value
Unknown
CVE-2023-28017
Disclosure Date: December 07, 2023 (last updated February 25, 2025)
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
0
Attacker Value
Unknown
CVE-2023-47316
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.
0
Attacker Value
Unknown
CVE-2023-47315
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied tokens.
0
Attacker Value
Unknown
CVE-2023-47314
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Headwind MDM Web panel 5.22.1 is vulnerable to cross-site scripting (XSS). The file upload function allows APK and arbitrary files to be uploaded. By exploiting this issue, attackers may upload HTML files and share the download URL pointing to these files with the victims. As the file download function returns the file in inline mode, the victim’s browser will immediately render the content of the HTML file as a web page. As a result, the uploaded client-side code will be evaluated and executed in the victim’s browser, allowing attackers to perform common XSS attacks.
0
Attacker Value
Unknown
CVE-2023-47313
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploaded temporary file to the file directory during the file upload process. This API call receives two input parameters, such as path and localPath. The first one refers to the temporary file with an absolute path without validating it. Attackers may modify this API call by referring to arbitrary files. As a result, arbitrary files can be moved to the files directory and so they can be downloaded.
0
Attacker Value
Unknown
CVE-2023-47312
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.
0
Attacker Value
Unknown
CVE-2023-37533
Disclosure Date: November 09, 2023 (last updated February 25, 2025)
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
0
Attacker Value
Unknown
CVE-2023-37532
Disclosure Date: October 23, 2023 (last updated February 25, 2025)
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2023-4488
Disclosure Date: October 20, 2023 (last updated February 25, 2025)
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
0
Attacker Value
Unknown
CVE-2023-37503
Disclosure Date: October 19, 2023 (last updated February 25, 2025)
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
0