Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-39612: Potential XSS in FileBrowser leads to Admin account takeover in Filebrowser · Issue #2570 · filebrowser/filebrowser

A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.

CVE
#xss#vulnerability#web#js#java#auth
CVE-2023-39777: [POC] [CVE-2023-39777]

A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.

CVE-2023-41436: CSZ-CMS-Stored-XSS---Pages-Content/README.md at main · sromanhu/CSZ-CMS-Stored-XSS---Pages-Content

Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component.

CVE-2023-4983

A vulnerability was found in app1pro Shopicial up to 20230830. It has been declared as problematic. This vulnerability affects unknown code of the file search. The manipulation of the argument from with the input comments</script>'"><img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239794 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Academy LMS 6.2 Cross Site Scripting

Academy LMS version 6.2 suffers from a cross site scripting vulnerability.

Italia Mediasky CMS 2.0 Cross Site Scripting

Italia Mediasky CMS version 2.0 suffers from a cross site scripting vulnerability.

CVE-2023-4663

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS.This issue affects Saphira Connect: before 9.

GHSA-jp3c-g46v-jg2c: LibreNMS Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.

GHSA-qjpw-rg56-jh8v: LibreNMS Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

GHSA-qxrq-376q-p39h: LibreNMS Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.