Show filters
744 Total Results
Displaying 91-100 of 744
Sort by:
Attacker Value
Unknown

CVE-2024-28135

Disclosure Date: May 14, 2024 (last updated January 24, 2025)
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
0
Attacker Value
Unknown

CVE-2024-28134

Disclosure Date: May 14, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected. 
0
Attacker Value
Unknown

CVE-2024-28133

Disclosure Date: May 14, 2024 (last updated January 24, 2025)
A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 
0
Attacker Value
Unknown

CVE-2024-34422

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trinhtuantai Viet Affiliate Link allows Stored XSS.This issue affects Viet Affiliate Link: from n/a through 1.2.
0
Attacker Value
Unknown

CVE-2024-4538

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket by creating a specific request with the ticket reference ID, leading to the exposure of sensitive user data.
0
Attacker Value
Unknown

CVE-2024-4537

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.
0
Attacker Value
Unknown

CVE-2024-2039

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post(v2) block title tag in all versions up to, and including, 3.12.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-30262

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
Attacker Value
Unknown

CVE-2024-28235

Disclosure Date: April 09, 2024 (last updated January 18, 2025)
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.
Attacker Value
Unknown

CVE-2024-28234

Disclosure Date: April 09, 2024 (last updated January 06, 2025)
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.