Tag
#php
NanoCMS version 0.4 suffers from an authenticated remote code execution vulnerability.
CuteEditor For PHP version 6.6 suffers from a directory traversal vulnerability.
WordPress Duplicator plugin versions 1.4.6 and below suffer from a backup disclosure vulnerability.
WordPress Duplicator plugin versions 1.4.7 and below suffer from an information disclosure vulnerability.
CodeIgniter CMS version 4.2.0 suffers from a remote SQL injection vulnerability.
WordPress SeatReg plugin version 1.23.0 suffers from an open redirection vulnerability.
Crime Reporting System version 1.0 suffers from a remote SQL injection vulnerability.
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.