Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-35501: GitHub - afine-com/CVE-2022-35501: Stored Cross-site Scripting (XSS) in blog-post creation functionality in Amasty Blog Pro for Magento 2

Stored Cross-site Scripting in Amasty Blog Pro 2.10.4 and 2.10.4 creates post functionality and lower versions.

CVE
#xss#git#java
CVE-2022-45150: Official Moodle git projects - moodle.git/search

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.

CVE-2022-45151

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Top Cyber Threats Facing E-Commerce Sites This Holiday Season

Delivering a superior customer experience is essential for any e-commerce business. For those companies, there's a lot at stake this holiday season. According to Digital Commerce 360, nearly $1.00 of every $4.00 spent on retail purchases during the 2022 holiday season will be spent online, resulting in $224 billion in e-commerce sales. To ensure your e-commerce site is ready for the holiday rush

CVE-2022-45472: GitHub - nicbrinkley/CVE-2022-45472: DOM Based XSS

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

GHSA-58rj-w2qf-qjg7: Cross-site Scripting in Backdrop CMS

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE-2022-37421: CVE-2022-37421 Stored XSS in custom meta tags

Silverstripe silverstripe/cms through 4.11.0 allows XSS.

CVE-2022-38147: CVE-2022-38147 XSS via uploaded gpx file

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).

CVE-2022-42095: [Declined]Backdrop-XSS-at-Pages - GrimTheRipper - Medium

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.