π¨ CVE-2021-43334
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
π@cveNotify
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
π@cveNotify
Cygenta-2020
Notes from a Pentester: How we found 2 new BuddyBoss vulnerabilities
Read how we discovered two Wordpress plugin vulnerabilities: CVE-2021-43334 and CVE-2021-44692.
π¨ CVE-2021-45975
In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.
π@cveNotify
In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.
π@cveNotify
π¨ CVE-2021-46141
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
π@cveNotify
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
π@cveNotify
GitHub
[CVE-2021-46141] .hostText memory is not properly duped/freed in uriNormalizeSyntax*, uriMakeOwner*, uriFreeUriMembers* for someβ¦
A bug was found within the uriparser. Though it might not be an intended use of the relevant API, the bug can still produce critical issues within a program using uriparser. It would be best if the...
π¨ CVE-2021-45334
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
π@cveNotify
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
π@cveNotify
Packetstormsecurity
Online Thesis Archiving System 1.0 SQL Injection / Cross Site Scripting β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2022-22852
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.
π@cveNotify
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.
π@cveNotify
GitHub
CVE-2022-22852/CVE-2022-22852.md at main Β· Sant268/CVE-2022-22852
Contribute to Sant268/CVE-2022-22852 development by creating an account on GitHub.
π¨ CVE-2022-21686
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
π@cveNotify
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
π@cveNotify
GitHub
Release PrestaShop 1.7.8.3 Β· PrestaShop/PrestaShop
This release fixes 25 bugs and regressions and 1 security fix reported on version 1.7.8.2.
Security issue fixed
#GHSA-mrq4-7ch7-2465: Server Side Twig Template Injection
Full Changelog
Click her...
Security issue fixed
#GHSA-mrq4-7ch7-2465: Server Side Twig Template Injection
Full Changelog
Click her...
π¨ CVE-2021-46336
There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.
π@cveNotify
There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.
π@cveNotify
GitHub
Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at jerryscript/jerry-core/parser/js/js-parser-expr.c(parser_parse_β¦
JerryScript revision Commit: a6ab5e9 Version: v3.0.0 Build platform Ubuntu 18.04.5 LTS (Linux 4.19.128-microsoft-standard x86_64) Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps pyth...
π¨ CVE-2021-46329
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
π@cveNotify
Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
π@cveNotify
GitHub
SEGV (/usr/local/bin/xst+0xdfee5f) in _fini Β· Issue #768 Β· Moddable-OpenSource/moddable
Moddable-XS revision Commit: 2f93df29 Version: 11.5.0 32 4 Build environment Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps cd ~/moddable/xs/makefiles/lin make -f xst.mk Test case p...
π¨ CVE-2021-33966
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.
π@cveNotify
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.
π@cveNotify
Packetstormsecurity
Spotweb-Develop 1.4.9 Cross Site Scripting β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2022-22888
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.
π@cveNotify
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.
π@cveNotify
GitHub
Stack-overflow in ecma-objects (ecma_op_object_find_own) Β· Issue #4848 Β· jerryscript-project/jerryscript
JerryScript revision 4592143 Build platform Ubuntu 18.04.5 LTS (Linux 4.19.128-microsoft-standard x86_64) Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps ./tools/build.py --clean --d...
π¨ CVE-2022-22890
There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.
π@cveNotify
There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.
π@cveNotify
GitHub
Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' in js-scanner-utilβ¦
JerryScript revision 4592143 Build platform Ubuntu 18.04.5 LTS (Linux 4.19.128-microsoft-standard x86_64) Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps ./tools/build.py --clean --d...
π¨ CVE-2021-44593
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
π@cveNotify
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
π@cveNotify
SourceCodester
Simple College Website using HTML/PHP/MySQLi with Source Code
Project: Simple College Website using HTML/PHP/MySQLi with Source Code
π¨ CVE-2021-40247
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
π@cveNotify
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
π@cveNotify
SourceCodester
Budget and Expense Tracker System in PHP Free Source Code
Introduction This is a PHP Project entitled Budget and Expense Tracker System. This system is a web-based application that manages your personal/small business budget and expenses. With this, you can easily track the entries budget and expenses by category.β¦
π¨ CVE-2022-22891
Jerryscript 3.0.0 was discovered to contain a SEGV vulnerability via ecma_ref_object_inline in /jerry-core/ecma/base/ecma-gc.c.
π@cveNotify
Jerryscript 3.0.0 was discovered to contain a SEGV vulnerability via ecma_ref_object_inline in /jerry-core/ecma/base/ecma-gc.c.
π@cveNotify
GitHub
SEGV in ecma_ref_object_inline of ecma-gc.c Β· Issue #4871 Β· jerryscript-project/jerryscript
JerryScript revision Commit: 51da1551 Version: v3.0.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps ./tools/build.py --clean --debug --profile=es2015-subset --compil...
π¨ CVE-2022-22892
There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (value) || ecma_is_value_object (value)' failed at jerry-core/ecma/base/ecma-helpers-value.c in Jerryscripts 3.0.0.
π@cveNotify
There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (value) || ecma_is_value_object (value)' failed at jerry-core/ecma/base/ecma-helpers-value.c in Jerryscripts 3.0.0.
π@cveNotify
GitHub
Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_numberβ¦
JerryScript revision Commit: 51da1551 Version: v3.0.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps ./tools/build.py --clean --debug --profile=es2015-subset --compil...
π¨ CVE-2022-22893
Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.
π@cveNotify
Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.
π@cveNotify
GitHub
Stack-overflow in vm_loop.lto_priv.304 of vm.c Β· Issue #4901 Β· jerryscript-project/jerryscript
JerryScript revision Commit: 42523bd6 Version: v3.0.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps python ./tools/build.py --clean --debug --compile-flag=-fsanitize...
π¨ CVE-2022-22894
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.
π@cveNotify
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.
π@cveNotify
GitHub
Stack-overflow in ecma_lcache_lookup (ecma-lcache.c) Β· Issue #4890 Β· jerryscript-project/jerryscript
JerryScript revision Commit: 51da1551 Version: v3.0.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps ./tools/build.py --clean --debug --compile-flag=-fsanitize=addres...
π¨ CVE-2022-22895
Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.
π@cveNotify
Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.
π@cveNotify
GitHub
Fix buffer overflow in string radix conversion by rerobika Β· Pull Request #4850 Β· jerryscript-project/jerryscript
JerryScript-DCO-1.0-Signed-off-by: Robert Fancsik robert.fancsik@h-lab.eu
π¨ CVE-2021-30960
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
π@cveNotify
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
π@cveNotify
Apple Support
About the security content of watchOS 8.3
This document describes the security content of watchOS 8.3.
π¨ CVE-2021-30946
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. A malicious application may be able to bypass certain Privacy preferences.
π@cveNotify
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. A malicious application may be able to bypass certain Privacy preferences.
π@cveNotify
Apple Support
About the security content of watchOS 8.3
This document describes the security content of watchOS 8.3.
π¨ CVE-2022-21682
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running `flatpak build` against it will gain those permissions. Normally this will not be done, so this is not problem. However, if `--mirror-screenshots-url` is specified, then flatpak-builder will launch `flatpak build --nofilesystem=host appstream-utils mirror-screenshots` after finalization, which can lead to issues even with the `--nofilesystem=host` protection. In normal use, the only issue is that these empty directories can be created wherever the user has write permissions. However, a malicious application could replace the `appstream-util` binary and potentially do something more hostile. This has been resolved in Flatpak 1.12.3 and 1.10.6 by changing the behaviour of `--nofilesystem=home` and `--nofilesystem=host`.
π@cveNotify
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running `flatpak build` against it will gain those permissions. Normally this will not be done, so this is not problem. However, if `--mirror-screenshots-url` is specified, then flatpak-builder will launch `flatpak build --nofilesystem=host appstream-utils mirror-screenshots` after finalization, which can lead to issues even with the `--nofilesystem=host` protection. In normal use, the only issue is that these empty directories can be created wherever the user has write permissions. However, a malicious application could replace the `appstream-util` binary and potentially do something more hostile. This has been resolved in Flatpak 1.12.3 and 1.10.6 by changing the behaviour of `--nofilesystem=home` and `--nofilesystem=host`.
π@cveNotify
GitHub
CVE-2022-21682: flatpak-builder --mirror-screenshots-url can access files outside the build directory
flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running `flatpak build` against it will ga...