Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-43194: CVE-2023-43194: Submitty Incorrect Access Control Vulnerability Report

Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.

CVE
#vulnerability#js#auth
CVE-2023-39057: CVE-reports/CVE-2023-39057.md at main · syz913/CVE-reports

An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39054: CVE-reports/CVE-2023-39054.md at main · syz913/CVE-reports

An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39053: 服部屋

An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39051: CVE-reports/CVE-2023-39051.md at main · syz913/CVE-reports

An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39042: CVE-reports/CVE-2023-39042.md at main · syz913/CVE-reports

An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39048: CVE-reports/CVE-2023-39048.md at main · syz913/CVE-reports

An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39050: ダイキョーバリュー福江店

An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39047: shouzu sweets oz

An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-31579: JWTissues/lamp issue.md at main · xubowenW/JWTissues

Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.