Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-37280: Fix xss in admin login 2fa setup page by aryaantony92 · Pull Request #147 · pimcore/admin-ui-classic-bundle

Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been patched in version 1.0.3.

CVE
#xss#vulnerability#js#git#auth
CVE-2023-33171

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-34089: Release v0.27.3 · decidim/decidim

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.6.

Mastery LMS 1.2 Cross Site Scripting

Mastery LMS version 1.2 suffers from a cross site scripting vulnerability.

Academy LMS 5.15 Cross Site Scripting

Academy LMS version 5.15 suffers from a cross site scripting vulnerability.

Articart 2.0.1 Cross Site Scripting / Open Redirection

Articart version 2.0.1 suffers from cross site scripting and open redirection vulnerabilities.

Atlas Business Directory Listing 2.13 Cross Site Scripting

Atlas Business Directory Listing version 2.13 suffers from cross site scripting vulnerabilities.

Ekushey Project Manager CRM 5.0 Cross Site Scripting

Ekushey Project Manager CRM version 5.0 suffers from a persistent cross site scripting vulnerability.

GHSA-f44m-65h3-99vc: tarteaucitron.js vulnerable to Cross-site Scripting

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

CVE-2023-3620: Filter the attr to avoid possible XSS vulnerability Fix #1132 · AmauriC/tarteaucitron.js@c4c2fcf

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.