Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-53730
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Hodge Silver April's Call Posts allows Stored XSS.
This issue affects April's Call Posts: from n/a through 2.1.1.
0
Attacker Value
Unknown
CVE-2023-38877
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This allows an attacker to reset other users' passwords.
0
Attacker Value
Unknown
CVE-2023-38874
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may visit the web shell and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2023-38873
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.
0
Attacker Value
Unknown
CVE-2023-38872
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
0
Attacker Value
Unknown
CVE-2023-38871
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to determine whether a user or email address is valid, or brute force valid usernames and email addresses.
0
Attacker Value
Unknown
CVE-2023-38870
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2021-36761
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
0
Attacker Value
Unknown
CVE-2019-11628
Disclosure Date: May 01, 2019 (last updated November 27, 2024)
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.
0
Attacker Value
Unknown
CVE-2014-100026
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in readme.php in the April's Super Functions Pack plugin before 1.4.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information.
0