‼ CVE-2023-3871 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-26045 ‼
📖 Read
via "National Vulnerability Database".
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk. This issue is patched in version 2.8.7. As a workaround, site maintainers can cherry pick the fix into their codebase to patch the exploit.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3879 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/del_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235241 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33777 ‼
📖 Read
via "National Vulnerability Database".
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23568 ‼
📖 Read
via "National Vulnerability Database".
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields.This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior📖 Read
via "National Vulnerability Database".
‼ CVE-2023-38745 ‼
📖 Read
via "National Vulnerability Database".
Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an attacker to create or overwrite arbitrary files, depending on the privileges of the process running Pandoc. It only affects systems that pass untrusted user input to Pandoc and allow Pandoc to be used to produce a PDF or with the --extract-media option. NOTE: this issue exists because of an incomplete fix for CVE-2023-35936 (failure to properly account for double encoded path names).📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3880 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/del_service.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235242 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22363 ‼
📖 Read
via "National Vulnerability Database".
A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group.This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)📖 Read
via "National Vulnerability Database".
‼ CVE-2023-37361 ‼
📖 Read
via "National Vulnerability Database".
REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3877 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument cost leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235239.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32232 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window, obtaining a full SYSTEM command prompt window. This results in complete compromise via arbitrary SYSTEM code execution (elevation of privileges).📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25074 ‼
📖 Read
via "National Vulnerability Database".
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies.This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6),vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32639 ‼
📖 Read
via "National Vulnerability Database".
Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32231 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets executed out of a subfolder in C:\Windows\Temp. A standard user can create the folder and path file ahead of time and obtain elevated code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3876 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3874 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, was found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235236.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3878 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235240.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3875 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in Campcodes Beauty Salon Management System 0.1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/del_feedback.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235237 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-3873 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235235.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21405 ‼
📖 Read
via "National Vulnerability Database".
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis NetworkIntercoms when communicating over OSDP, highlighting that the OSDP message parser crashesthe pacsiod process, causing a temporary unavailability of the door-controlling functionalitiesmeaning that doors cannot be opened or closed. No sensitive or customer data can be extractedas the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-35066 ‼
📖 Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection.This issue affects E-Invoice Approval System: before v.20230701.📖 Read
via "National Vulnerability Database".