Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-43233: bug_report/SQLi-1.md at main · HKD01l/bug_report

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.

CVE
#sql#vulnerability#windows#php#auth#firefox
CVE-2022-43230: bug_report/SQLi-1.md at main · HKD01l/bug_report

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.

CVE-2022-2864: Changeset 2772352 for demon-image-annotation – WordPress Plugin Repository

The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7. This is due to missing nonce validation in the ~/includes/settings.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-43170: Stored Cross Site Scripting Vulnerability on "Dashboard Configuration" in rukovoditel 3.2.1 · Issue #6 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".

CVE-2022-43169: Stored Cross Site Scripting Vulnerability on "Users Access Groups" in rukovoditel 3.2.1 · Issue #3 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".

CVE-2022-43165: Stored Cross Site Scripting Vulnerability on "Global Variables" in rukovoditel 3.2.1 · Issue #5 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".

CVE-2022-43166: Stored Cross Site Scripting Vulnerability on "Entities List" in rukovoditel 3.2.1 · Issue #2 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".

CVE-2022-43167: Stored Cross Site Scripting Vulnerability on "Users Alerts" in rukovoditel 3.2.1 · Issue #7 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVE-2022-43164: Stored Cross Site Scripting Vulnerability on "Global Lists" in rukovoditel 3.2.1 · Issue #4 · anhdq201/rukovoditel

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVE-2022-3400: Vulnerability Advisories Continued - Wordfence

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.