Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-33661: XSS exists in the group report page · Issue #6474 · ChurchCRM/CRM

Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.

CVE
#sql#xss#vulnerability#web#windows#linux#java#php#firefox
CVE-2023-36474: Making app CNAME optional by Mzack9999 · Pull Request #155 · projectdiscovery/interactsh

Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as default, which intended to used for hosting interactsh web client using GitHub pages. This is a security issue with a self-hosted interactsh server in which the user may not have configured a web client but still have a CNAME entry pointing to GitHub pages, making them vulnerable to subdomain takeover. This allows a threat actor to host / run arbitrary client side code (cross-site scripting) in a user's browser when browsing the vulnerable subdomain. Version 1.0.0 fixes this issue by making CNAME optional, rather than default.

CVE-2021-25828: Reflected Cross-Site Scripting (XSS) (CVE-2021-25828) · Issue #3785 · MediaBrowser/Emby

Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.

NewsLetter Script 2.4 Cross Site Scripting

NewsLetter Script version 2.4 suffers from a cross site scripting vulnerability.

Red Hat Security Advisory 2023-3885-01

Red Hat Security Advisory 2023-3885-01 - Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.4 on RHEL 9 serves as a replacement for Red Hat Single Sign-On 7.6.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include a cross site scripting vulnerability.

Simple Forum 2.7 Cross Site Scripting

Simple Forum version 2.7 suffers from a cross site scripting vulnerability.