Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2021-30134
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
0
Attacker Value
Unknown
CVE-2020-13476
Disclosure Date: December 28, 2020 (last updated February 22, 2025)
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
0
Attacker Value
Unknown
CVE-2020-11560
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
0
Attacker Value
Unknown
CVE-2020-11561
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
0
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2019-16251
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
0
Attacker Value
Unknown
CVE-2019-16282
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
0