Tag
#webkit
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Grawlix version 1.5.1 suffers from a cross site scripting vulnerability.
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
Jorani version 1.0.3 suffers from a cross site scripting vulnerability.
Uvdesk version 1.1.4 suffers from a persistent cross site scripting vulnerability.
Dolibarr version 17.0.1 suffers from a persistent cross site scripting vulnerability.
Global Multi School Management System Express version 1.0 suffers from a remote SQL injection vulnerability.
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.