Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-34837: CVE-2023-34837/README.md at main · sahiloj/CVE-2023-34837

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.

CVE
#xss#vulnerability#windows#auth
CVE-2023-34838: CVE-2023-34838/README.md at main · sahiloj/CVE-2023-34838

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.

CVE-2023-34836: CVE-2023-34836/README.md at main · sahiloj/CVE-2023-34836

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

CVE-2023-26274: Security Bulletin: IBM QRadar SIEM is vulnerable to Cross Site Scripting (XSS) (CVE-2023-26274)

IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144.

CVE-2023-34835: CVE-2023-34835/README.md at main · sahiloj/CVE-2023-34835

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

CVE-2023-32339

IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587.

CVE-2023-34830: GitHub - leekenghwa/CVE-2023-34830---Reflected-XSS-found-in-I-doit-Open-v24-and-below

i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

Rocket LMS 1.7 Cross Site Scripting

Rocket LMS version 1.7 suffers from a persistent cross site scripting vulnerability.

ONEST CRM 1.0 Cross Site Scripting

ONEST CRM version 1.0 suffers from a persistent cross site scripting vulnerability.

Office Suite Premium 10.9.1.42602 Cross Site Scripting

Office Suite Premium version 10.9.1.42602 suffers from a cross site scripting vulnerability.