Show filters
175 Total Results
Displaying 91-100 of 175
Sort by:
Attacker Value
Unknown

CVE-2022-1952

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.
Attacker Value
Unknown

CVE-2022-29923

Disclosure Date: May 12, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
Attacker Value
Unknown

CVE-2021-24965

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
Attacker Value
Unknown

CVE-2021-44091

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
Attacker Value
Unknown

CVE-2021-24722

Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-25654

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
Attacker Value
Unknown

CVE-2021-25655

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25656

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25650

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services
Attacker Value
Unknown

CVE-2021-25651

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services