Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-1940

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVE
#xss#vulnerability#git#java#jira
CVE-2022-30861: Cross Site Scripting · Issue #24 · fudforum/FUDforum

FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.

CVE-2021-42245: Create Page XSS · Issue #69 · flatCore/flatCore-CMS

FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.

GHSA-r7jw-mg27-j839: Cross-site Scripting in FacturaScripts

FacturaScripts 2022.08 and prior is vulnerable to cross-site scripting. A patch is available on the `master` branch of the repository and anticipated to be part of version 2022.09.

CVE-2022-29770: There is a stored XSS vulnerability in the task management of xxl-job · Issue #2836 · xuxueli/xxl-job

XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.

CVE-2022-26493: Auth Bypass via SAML Attacks

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. This vulnerability is not mitigated by configuring the module to enforce signatures or certificate checks. Xecurify recommends updating miniOrange modules to their most recent versions. This vulnerability is present in paid versions of the miniOrange Drupal SAML SP product affecting Drupal 7, 8, and 9.

Contao 4.13.2 Cross Site Scripting

Contao version 4.13.2 suffers from a cross site scripting vulnerability.

CVE-2022-1988: - Añadida comprobación de html en descripción al test unitario del mo… · NeoRazorX/facturascripts@93fc65c

Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.

GHSA-4qf6-vpj8-p4r6: Cross site scripting in SSCMS

siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

GHSA-8rp2-j3vj-hgj4: Cross site scripting in Jfinal

A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.