CVE tracker
280 subscribers
3.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-52920 - Innoshop IDOR

CVE ID : CVE-2025-52920
Published : June 23, 2025, 12:15 p.m. | 4 hours ago
Description : Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products on the website. To be specific, an attacker could view the order details of any order by browsing to /en/account/orders/_ORDER_ID_ or use the address and billing information of other customers by manipulating the shipping_address_id and billing_address_id parameters when making an order (this information is then reflected in the receipt). Additionally, an attacker could delete the reviews of other users by sending a DELETE request to /en/account/reviews/_REVIEW_ID.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52921 - Innoshop File Manager Code Execution Vulnerability

CVE ID : CVE-2025-52921
Published : June 23, 2025, 12:15 p.m. | 4 hours ago
Description : In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uploaded files are image files. The application relies on frontend checks to restrict the administrator from changing the extension of uploaded files to .php. This restriction is easily bypassed with any proxy tool (e.g., BurpSuite). Once the attacker renames the file, and gives it the .php extension, a GET request can be used to trigger the execution of code on the server.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52922 - Innoshop Directory Traversal Remote File Inclusion

CVE ID : CVE-2025-52922
Published : June 23, 2025, 12:15 p.m. | 4 hours ago
Description : Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server via the /api/file_manager/directories endpoint, (3) read arbitrary files from the server by copying the file to a readable location within the application via the /api/file_manager/copy_files endpoint, {4) delete arbitrary files from the server via a DELETE request to /api/file_manager/files, or (5) create arbitrary files on the server by uploading them and then leveraging the /api/file_manager/move_files endpoint to move them anywhere in the filesystem.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6512 - BRAIN2 Remote Command Execution Vulnerability

CVE ID : CVE-2025-6512
Published : June 23, 2025, 1:15 p.m. | 3 hours ago
Description : On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6513 - BRAIN2 Windows Configuration File Decryption Vulnerability

CVE ID : CVE-2025-6513
Published : June 23, 2025, 1:15 p.m. | 3 hours ago
Description : Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2171 - Aviatrix Controller Password Reset PIN Brute Force Vulnerability

CVE ID : CVE-2025-2171
Published : June 23, 2025, 2:15 p.m. | 2 hours ago
Description : Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2172 - Aviatrix Controller Command Injection

CVE ID : CVE-2025-2172
Published : June 23, 2025, 2:15 p.m. | 2 hours ago
Description : Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52542 - Apache Struts Remote Code Execution Vulnerability

CVE ID : CVE-2025-52542
Published : June 23, 2025, 2:15 p.m. | 2 hours ago
Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-47297 - NCR Terminal Handler Command Injection

CVE ID : CVE-2023-47297
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-47298 - "NCR Terminal Handler Information Disclosure Vulnerability"

CVE ID : CVE-2023-47298
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-48978 - NCR ITM Web Terminal Remote Code Execution Vulnerability

CVE ID : CVE-2023-48978
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46101 - Beakon Software Beakon Learning Management System SCORM SQL Injection

CVE ID : CVE-2025-46101
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48700 - Zimbra Collaboration Cross-Site Scripting (XSS) Vulnerability

CVE ID : CVE-2025-48700
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52875 - JetBrains TeamCity DOM-Based XSS

CVE ID : CVE-2025-52875
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52876 - JetBrains TeamCity Reflected Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-52876
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52877 - JetBrains TeamCity Reflected XSS Vulnerability

CVE ID : CVE-2025-52877
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52878 - JetBrains TeamCity Unauthenticated Username Exposure

CVE ID : CVE-2025-52878
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52879 - JetBrains TeamCity Reflected XSS in NPM Registry Integration

CVE ID : CVE-2025-52879
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52967 - MLflow Gateway Proxy Handler Path Validation Bypass

CVE ID : CVE-2025-52967
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52968 - xdg-utils CSRF Vulnerability

CVE ID : CVE-2025-52968
Published : June 23, 2025, 3:15 p.m. | 1 hour ago
Description : xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-47032 - NCR Terminal Handler Remote Code Execution Vulnerability

CVE ID : CVE-2023-47032
Published : June 23, 2025, 4:15 p.m. | 4 hours ago
Description : Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...