Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-8945
Disclosure Date: September 17, 2024 (last updated September 26, 2024)
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
0
Attacker Value
Unknown
CVE-2024-0545
Disclosure Date: January 15, 2024 (last updated January 23, 2024)
A vulnerability classified as problematic was found in CodeCanyon RISE Rise Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250714 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2019-18884
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
0
Attacker Value
Unknown
CVE-2017-17999
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
0
Attacker Value
Unknown
CVE-2017-11182
Disclosure Date: July 12, 2017 (last updated November 26, 2024)
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.
0
Attacker Value
Unknown
CVE-2017-11181
Disclosure Date: July 12, 2017 (last updated November 26, 2024)
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.
0