Show filters
71 Total Results
Displaying 1-10 of 71
Sort by:
Attacker Value
Unknown

CVE-2024-43974

Disclosure Date: November 01, 2024 (last updated November 09, 2024)
Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2.
Attacker Value
Unknown

CVE-2020-36633

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this issue. The name of the patch is cd18d8b1afe464ae6626832496f4e070bac4c58f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216879.
Attacker Value
Unknown

CVE-2020-5558

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
Attacker Value
Unknown

CVE-2020-5557

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2012-2724

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
Attacker Value
Unknown

CVE-2019-11447

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
0
Attacker Value
Unknown

CVE-2013-4447

Disclosure Date: November 01, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.
0
Attacker Value
Unknown

CVE-2012-5537

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
0
Attacker Value
Unknown

CVE-2009-4708

Disclosure Date: March 15, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4707

Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0