Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-39578: Zenaio-xss · Issue #1 · anh91/Zenario-xss

A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.

CVE
#xss#vulnerability#web

Summary
hi team,
I found a small Stored XSS

Info

Zenario 9.4

Step 1:
Login to account https://demo.zenar.io/admin

Step 2:
In the tab menu click on event and create a new event

Step 3:
Inject payload to Menu navigation text, choice menu note menu (simple choice account ), and save the event

Step 4:
Go to Menu navigation and click on account. And move the mouse to the event then the payload is executed

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907