Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-45017: gozan10 - Overview

A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.

CVE
#xss#vulnerability#web#git
  • 2022
  • 2021
  • 2020

Contribution activity

November 2022

Created 8 commits in 3 repositories

  • gozan10/baiTapCongNgheWeb 3 commits

  • gozan10/rac 3 commits

  • gozan10/cve 2 commits

Created 3 repositories

  • gozan10/rac HTML Nov 8
  • gozan10/cve Nov 3
  • gozan10/baiTapCongNgheWeb HTML Nov 3

Opened their first issue on GitHub in gozan10/baiTapCongNgheWeb Public

Nov 3

First issue

cve

Created an issue in WBCE/WBCE_CMS that received 1 comment

Nov 4

XSS via No Results in Search Settings

Hi team, i find small XSS in No Results field Step: First choose Settings and find Search Settings field then choose button Show Advanced Options I…

1 comment

Opened 7 other issues in 2 repositories

gozan10/cve 5 open

  • CVE WBCE_4 Nov 4
  • CVE_WBCE_3 Nov 4
  • CVE_WBCE_2 Nov 4
  • CVE_WBCE_1 Nov 4
  • CVE_WBCE Nov 3

WBCE/WBCE_CMS 2 open

  • XSS via modul post loop in Pages Nov 5
  • Bypass account protection Nov 5

Seeing something unexpected? Take a look at the GitHub profile guide.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907