Tag
#php
SugarCRM versions 12.2.0 and below suffers from a multiple step remote shell upload vulnerability.
GEN Security+ version 4.0 suffers from a remote SQL injection vulnerability.
Geeklog version 2.1.0b1 suffers from a database disclosure vulnerability.
G and G Corporate CMS version 1.0 suffers from a cross site scripting vulnerability.
FreshRSS version 1.11.1 suffers from an html injection vulnerability.
Forum Fire Soft Board version 0.3.0 suffers from a cross site scripting vulnerability.
Forma LMS version 1.4 suffers from a database disclosure vulnerability.
Foodiee CMS version 1.0.1 suffers from an insecure direct object reference vulnerability.
Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaign
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.