Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-25988: [#2052] Fix stored XSS in Notifications · ifmeorg/ifme@720a470

In “ifme�, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.

CVE
#xss#vulnerability#java
CVE-2021-25990: WhiteSource Vulnerability Database

In “ifme�, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

CVE-2021-45813

SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.

CVE-2021-45812: NUUO – Google Drive

NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.

CVE-2021-45903: cves/CVE-2021-45903.md at main · ach-ing/cves

A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.

CVE-2021-45425

Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

CVE-2021-45906: FS#4199 : Storage XSS

OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.

CVE-2020-21236: DamiCMS-v6.0.0-have-csrf-and-xss-Vulnerabilities-/README.md at master · wind-cyber/DamiCMS-v6.0.0-have-csrf-and-xss-Vulnerabilities-

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

CVE-2020-20944: some vulnerabilities in qibosoft(齐博CMS整站系统v7)_tnt阿信的博客-CSDN博客

An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.

CVE-2020-20946: some vulnerabilities in qibosoft(齐博CMS整站系统v7)_一个安全研究员-CSDN博客

Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.