Show filters
285 Total Results
Displaying 91-100 of 285
Sort by:
Attacker Value
Unknown
CVE-2022-46901
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
0
Attacker Value
Unknown
CVE-2022-46900
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries and set the executable path and parameters.
0
Attacker Value
Unknown
CVE-2022-46899
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The BaseController class, that each of the service controllers derives from, allows for the upload of arbitrary files. If the HTTP request is a multipart/form-data POST request, any parameters with a filename entry will have their content written to a file in the Vocera upload-staging directory with the specified filename in the parameter.
0
Attacker Value
Unknown
CVE-2022-46898
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. The filename provided is not properly sanitized and allows for the inclusion of a path-traversal payload that can be used to escape the intended Vocera restoration directory. An attacker could exploit this vulnerability to point to a crafted ZIP archive that contains SQL commands that could be executed against the database.
0
Attacker Value
Unknown
CVE-2023-35067
Disclosure Date: July 25, 2023 (last updated December 22, 2024)
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable.This issue affects E-Invoice Approval System: before v.20230701.
0
Attacker Value
Unknown
CVE-2023-35066
Disclosure Date: July 25, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection.This issue affects E-Invoice Approval System: before v.20230701.
0
Attacker Value
Unknown
CVE-2023-25439
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
0
Attacker Value
Unknown
CVE-2023-31458
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2023-25599
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
0
Attacker Value
Unknown
CVE-2023-31460
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
0