Show filters
98 Total Results
Displaying 1-10 of 98
Sort by:
Attacker Value
Unknown
CVE-2024-23563
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
0
Attacker Value
Unknown
CVE-2024-12885
Disclosure Date: January 25, 2025 (last updated January 25, 2025)
The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server and all their content.
0
Attacker Value
Unknown
CVE-2024-52340
Disclosure Date: November 18, 2024 (last updated November 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marty Thornley Photographer Connections allows Stored XSS.This issue affects Photographer Connections: from n/a through 1.3.1.
0
Attacker Value
Unknown
CVE-2024-42188
Disclosure Date: November 14, 2024 (last updated November 15, 2024)
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
0
Attacker Value
Unknown
CVE-2024-30106
Disclosure Date: October 28, 2024 (last updated November 09, 2024)
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
0
Attacker Value
Unknown
CVE-2024-30118
Disclosure Date: October 09, 2024 (last updated October 12, 2024)
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
0
Attacker Value
Unknown
CVE-2024-30112
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
0
Attacker Value
Unknown
CVE-2023-37541
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
0
Attacker Value
Unknown
CVE-2023-45707
Disclosure Date: June 08, 2024 (last updated June 09, 2024)
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
0
Attacker Value
Unknown
CVE-2024-30107
Disclosure Date: April 18, 2024 (last updated April 19, 2024)
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
0