Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-32503: The SICK Product Security Incident Response Team (SICK PSIRT)

Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

CVE
#xss#vulnerability#web
CVE-2022-26565: Security Issue - Cross Site Scripting (Stored) · Issue #35 · totaljs/cms

A cross-site scripting (XSS) vulnerability in Totaljs commit 95f54a5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

GitLab addresses critical account hijack bug

Monthly release also addresses pair of stored XSS flaws

CVE-2022-24181: Add support for limiting allowed hosts · Issue #7649 · pkp/pkp-lib

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVE-2021-43707: XSS · Issue #18 · maccmspro/maccms10

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

CVE-2021-42946: CVE-2021-42946: HTMLy 2.8.1 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

CVE-2021-42869: CVE-2021-42869: Chikitsa 2.0.2 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.

CVE-2021-42867: CVE-2021-42967: HTMLy 2.8.1 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.

CVE-2021-42868: CVE-2021-42868: Chikitsa 2.0.2 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .

CVE-2021-42866: CVE-2021-42866: Pixelimity 1.0 XSS vulnerability

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php