Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2021-32961

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.
Attacker Value
Unknown

CVE-2021-32957

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.
Attacker Value
Unknown

CVE-2021-32953

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.
Attacker Value
Unknown

CVE-2021-32949

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
Attacker Value
Unknown

CVE-2021-32945

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.
Attacker Value
Unknown

CVE-2021-32937

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.
Attacker Value
Unknown

CVE-2021-32933

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.
Attacker Value
Unknown

CVE-2012-2097

Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving "submitting saved results to a node."
0