Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-44598: CVE-mitre/CVE-2021-44598 at main · nu11secur1ty/CVE-mitre

Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.

CVE
#xss#vulnerability#git

Latest commit

@nu11secur1ty

Files

Permalink

Failed to load latest commit information.

Type

Name

Latest commit message

Commit time

CVE-2021-44598****Vendor****Software

Description:

Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.

[+] Payload:

students_view.php?SearchString=&current_view=TV&SortField=&SelectedID=u9mwghcdjf5gwzikfb8htcyea73duurxiyzoo&SelectedField=1&SortDirection=&FirstRecord=1m1p75%22%3e%3cscript%3ealert('hello.from.nu11secur1ty')%3c%2fscript%3ejiairgg3ecj

Proof and Exploit:

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907