Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2024-22648

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.
Attacker Value
Unknown

CVE-2024-22647

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
Attacker Value
Unknown

CVE-2024-22646

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
Attacker Value
Unknown

CVE-2024-22643

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.