Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-25169

Disclosure Date: February 28, 2024 (last updated February 15, 2025)
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
Attacker Value
Unknown

CVE-2020-19002

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.
Attacker Value
Unknown

CVE-2019-12366

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
Attacker Value
Unknown

CVE-2018-16632

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/.
0
Attacker Value
Unknown

CVE-2017-17689

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
0
Attacker Value
Unknown

CVE-2017-13995

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access sensitive information such as HMI pages or modify PLC variables.
0
Attacker Value
Unknown

CVE-2014-6961

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The SudaniNet (aka com.sudaninet.wtwqiqbegq_btwlda) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0