Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-12512
Disclosure Date: January 25, 2025 (last updated January 25, 2025)
The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-30543
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId` could be incorrect. For example, if a swapping application derives a wrapped token contract address from the `chainId` *and* a user has changed chains as part of their connection flow the application could cause the user to send funds to the incorrect address when wrapping. This issue has been addressed in PR #749 and is available in updated npm artifacts. There are no known workarounds for this issue. Users are advised to upgrade.
0
Attacker Value
Unknown
CVE-2022-3750
Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.
0
Attacker Value
Unknown
CVE-2022-1251
Disclosure Date: August 22, 2022 (last updated October 08, 2023)
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.
0
Attacker Value
Unknown
CVE-2022-32969
Disclosure Date: June 29, 2022 (last updated October 07, 2023)
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.
0
Attacker Value
Unknown
CVE-2022-1424
Disclosure Date: June 08, 2022 (last updated October 07, 2023)
The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.
0
Attacker Value
Unknown
CVE-2022-1241
Disclosure Date: June 08, 2022 (last updated October 07, 2023)
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2017-6048
Disclosure Date: May 19, 2017 (last updated November 26, 2024)
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the attacker breaking out of the jailed shell and gaining full access to the system.
0
Attacker Value
Unknown
CVE-2013-4749
Disclosure Date: July 01, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the UserTask Center, Messaging (sys_messages) extension 1.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0