Tag
#windows
POS Codekop version 2.0 suffers from a remote shell upload vulnerability.
The threat actors behind the DDoSia attack tool have come up with a new version that incorporates a new mechanism to retrieve the list of targets to be bombarded with junk HTTP requests in an attempt to bring them down. The updated variant, written in Golang, "implements an additional security mechanism to conceal the list of targets, which is transmitted from the [command-and-control] to the
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.
AppleZeed CMS version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
ApPHP MicroCMS version 1.0.1 re-embeds arbitrary content from the client into web pages.
ApnaTrademark CMS version 2.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Allhandsmarketing CMS version 3.01 suffers from a remote SQL injection vulnerability.
Allhandsmarketing LMS version 2.0 suffers from a cross site request forgery vulnerability.
Adveris CMS version 3.0 suffers from a cross site scripting vulnerability.
Advanced HRM version 1.6 allows for the reseting of the administrative password.