Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-56037

Disclosure Date: January 02, 2025 (last updated January 02, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Maruf Adnan Sami User Referral allows Reflected XSS.This issue affects User Referral: from n/a through 8.0.
0
Attacker Value
Unknown

CVE-2023-0926

Disclosure Date: August 24, 2024 (last updated September 27, 2024)
The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on tag names. This allows authenticated users, with editor-level permissions or greater to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, even when 'unfiltered_html' has been disabled.
Attacker Value
Unknown

CVE-2023-31302

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.
Attacker Value
Unknown

CVE-2023-31300

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
Attacker Value
Unknown

CVE-2023-31295

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
Attacker Value
Unknown

CVE-2023-31299

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.
Attacker Value
Unknown

CVE-2023-31296

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
Attacker Value
Unknown

CVE-2023-31294

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
Attacker Value
Unknown

CVE-2023-31293

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.
Attacker Value
Unknown

CVE-2023-31301

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.