Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2025-24541
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DK White Label allows Reflected XSS. This issue affects DK White Label: from n/a through 1.0.
0
Attacker Value
Unknown
CVE-2025-24534
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DPortfolio allows Reflected XSS. This issue affects DPortfolio: from n/a through 2.0.
0
Attacker Value
Unknown
CVE-2020-11682
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.
0
Attacker Value
Unknown
CVE-2020-11681
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.
0
Attacker Value
Unknown
CVE-2020-11680
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying alerts, creating/modifying users, etc.
0
Attacker Value
Unknown
CVE-2020-11679
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their account.
0
Attacker Value
Unknown
CVE-2002-0235
Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in plaintext in an error event.
0