Show filters
67 Total Results
Displaying 1-10 of 67
Sort by:
Attacker Value
Unknown
CVE-2024-6834
Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an attacker to handle the whole communication including user credentials.
0
Attacker Value
Unknown
CVE-2024-6833
Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
0
Attacker Value
Unknown
CVE-2023-51813
Disclosure Date: January 30, 2024 (last updated February 06, 2024)
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.
0
Attacker Value
Unknown
CVE-2023-39712
Disclosure Date: September 08, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
0
Attacker Value
Unknown
CVE-2023-39711
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
0
Attacker Value
Unknown
CVE-2023-39714
Disclosure Date: September 01, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.
0
Attacker Value
Unknown
CVE-2023-39710
Disclosure Date: September 01, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.
0
Attacker Value
Unknown
CVE-2023-39709
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.
0
Attacker Value
Unknown
CVE-2023-39708
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.
0
Attacker Value
Unknown
CVE-2023-39707
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.
0