Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-37461: metersphere 存在路径穿越漏洞

Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../` which may cause metersphere to attempt to overwrite an existing file in the defined location or to create a new file. Attackers would be limited to overwriting files that the metersphere process has access to. This issue has been addressed in version 2.10.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE
#csrf#vulnerability#web#windows#apple#js#auth#chrome#webkit
CVE-2023-37781: a security issue was found · Issue #10419 · emqx/emqx

An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.

Travelable 1.0 Cross Site Scripting

Travelable version 1.0 suffers from a persistent cross site scripting vulnerability.

BloodBank 1.1 SQL Injection

BloodBank version 1.1 suffers from a remote SQL injection vulnerability.

BloodBank 1.1 Cross Site Scripting

BloodBank version 1.1 suffers from a cross site scripting vulnerability.

Carlisting 1.6 Cross Site Scripting

Carlisting version 1.6 suffers from a cross site scripting vulnerability.

Carlisting 1.6 SQL Injection

Carlisting version 1.6 suffers from a remote SQL injection vulnerability.

RecipePoint 1.9 SQL Injection

RecipePoint version 1.9 suffers from a remote SQL injection vulnerability.

Lawyer CMS 1.6 Cross Site Scripting

Lawyer CMS version 1.6 suffers from a cross site scripting vulnerability.

JobSeeker 1.5 Cross Site Scripting

JobSeeker version 1.5 suffers from a cross site scripting vulnerability.