Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-43166: Stored Cross Site Scripting Vulnerability on "Entities List" in rukovoditel 3.2.1 · Issue #2 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".

CVE
#xss#vulnerability#web#php#auth
CVE-2022-43167: Stored Cross Site Scripting Vulnerability on "Users Alerts" in rukovoditel 3.2.1 · Issue #7 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVE-2022-43164: Stored Cross Site Scripting Vulnerability on "Global Lists" in rukovoditel 3.2.1 · Issue #4 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVE-2022-3400: Vulnerability Advisories Continued - Wordfence

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.

CVE-2021-38217: SEMCMS/semcms-1.2-sql-2.md at main · BigTiger2020/SEMCMS

SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.

CVE-2021-38730: SCSHOP/semcms-8.md at main · BigTiger2020/SCSHOP

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.

CVE-2021-38728: SCSHOP/semcms-9.md at main · BigTiger2020/SCSHOP

SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.

CVE-2021-37782: Employee Record Management System in PHP and MySQL PHPGurukul

Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.

CVE-2021-38734: SEMCMS外贸网站商城系统 SCSHOP_v1.1 更新

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.