Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-25408: Persistent cross-site scripting (XSS) in targeted towards web admin through /admin-panel1.php at via the parameter dpassword. · Issue #22 · kishan0725/Hospital-Management-System

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.

CVE
#xss#vulnerability#web#git
CVE-2022-23907: CMS Made Simple - Forge : CMS Made Simple Core

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

CVE-2022-25409: Persistent cross-site scripting (XSS) targeted towards web admin through /admin-panel1.php at via the parameter demail. · Issue #20 · kishan0725/Hospital-Management-System

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVE-2022-25407: Persistent cross-site scripting (XSS) in targeted towards web admin through /admin-panel1.php at via the parameter doctor. · Issue #21 · kishan0725/Hospital-Management-System

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.

CVE-2022-0743: Fixed entity sanitization for XSS detection · getgrav/grav@3dd0cab

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-25014: Reflected XSS vulnerability in the Dashboard page of logged-in user · Issue #283 · gamonoid/icehrm

Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.

CVE-2022-25015: Stored XSS vulnerability in dashboard of any logged-in user · Issue #285 · gamonoid/icehrm

A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.

CVE-2022-25013: Reflected XSS vulnerabilities in login.php -- can be used to leak passwords · Issue #284 · gamonoid/icehrm

Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.

CVE-2022-25642: Release v3.4.1 · byteball/obyte-gui-wallet

Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.

CVE-2022-24572: OpenSource/exploit_xss at main · nsparker1337/OpenSource

Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details.