Security
Headlines
HeadlinesLatestCVEs

Tag

#php

MyBB Favicon 1.0 Cross Site Scripting

MyBB Favicon plugin version 1.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#php#auth
Job Board 1.0 Shell Upload

Job Board version 1.0 suffers from a remote shell upload vulnerability.

PrestaShop Winbiz Payment Improper Limitation

PrestaShop Winbiz Payment module suffers from an improper limitation of a Pathname to a restricted directory.

Xenforo 2.2.13 Cross Site Scripting

Xenforo version 2.2.13 suffers from a persistent cross site scripting vulnerability.

CVE-2021-30205: dzzoffice 2.02.1_SC_UTF8 exists Unauthorized access vulnerability · Issue #184 · zyx0814/dzzoffice

Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.

CVE-2021-30203: dzzoffice 2.02.1_SC_UTF8 exists a XSS vulnerability · Issue #183 · zyx0814/dzzoffice

A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.

CVE-2023-2068

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

MCL-Net 4.3.5.8788 Information Disclosure

MCL-Net version 4.3.5.8788 suffers from an information disclosure vulnerability.

CVE-2023-3132: Changeset 2923512 for mainwp-child – WordPress Plugin Repository

The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a backup occurs and the deletion of the back-up files fail.

CVE-2023-3371: Helper.php in embedpress/tags/3.7.3/EmbedPress/Includes/Classes – WordPress Plugin Repository

The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.