π¨ CVE-2022-40797
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
π@cveNotify
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
π@cveNotify
GitLab
debian/php-cgi.conf Β· dc253886b5b2e9bc8d9e36db787abb083a667fd8 Β· Debian PHP Team / php Β· GitLab
PHP Packaging
π¨ CVE-2022-2387
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack
π@cveNotify
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack
π@cveNotify
WPScan
Easy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF
See details on Easy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF CVE 2022-2387. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
π@cveNotify
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
π@cveNotify
GitLab
Escape characters which do not belong into an URI/URL (Issue #390) (55e3c5fb) Β· Commits Β· Xfce / xfce4-settings Β· GitLab
In order to prevent argument injection
π¨ CVE-2022-43118
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
π@cveNotify
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
π@cveNotify
GitHub
Cross Site Scripting (XSS) in Install Β· Issue #86 Β· flatCore/flatCore-CMS
Describe the bug Cross Site Scripting (XSS) in the username section of the install page. version: 2.1.0 To Reproduce Steps to reproduce the behavior: Go to 'CMS Install Page' Insert into a ...
π¨ CVE-2022-43119
A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.
π@cveNotify
A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.
π@cveNotify
GitHub
POC/Create Clansphere 2011.4 "username" xss.md at main Β· sinemsahn/POC
Contribute to sinemsahn/POC development by creating an account on GitHub.
π¨ CVE-2022-2711
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.
π@cveNotify
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.
π@cveNotify
WPScan
WP All Import < 3.6.9 - Admin+ Directory traversal via file upload
See details on WP All Import < 3.6.9 - Admin+ Directory traversal via file upload CVE 2022-2711. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-3451
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
π@cveNotify
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
π@cveNotify
Wpscan
WPScan: WordPress Security
A WordPress vulnerability database for WordPress core security vulnerabilities, plugin vulnerabilities and theme vulnerabilities.
π¨ CVE-2022-3418
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
π@cveNotify
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files
π@cveNotify
WPScan
WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE
See details on WP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE CVE 2022-3418. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-3462
The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
π@cveNotify
The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
π@cveNotify
Wpscan
WPScan: WordPress Security
A WordPress vulnerability database for WordPress core security vulnerabilities, plugin vulnerabilities and theme vulnerabilities.
π¨ CVE-2022-3463
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
π@cveNotify
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
π@cveNotify
WPScan
FluentForm < 4.3.13 - CSV Injection
See details on FluentForm < 4.3.13 - CSV Injection CVE 2022-3463. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-43120
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
π@cveNotify
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.
π@cveNotify
GitHub
Cross Site Scripting (XSS) in Add Field Page Β· Issue #894 Β· intelliants/subrion
Describe the bug Cross Site Scripting (XSS) in the default value section of the Add Field page. version: 4.2.1 To Reproduce Steps to reproduce the behavior: Go to 'CMS Add Field page...
π¨ CVE-2022-3481
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection
π@cveNotify
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection
π@cveNotify
WPScan
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
See details on WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi CVE 2022-3481. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-3878
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.
π@cveNotify
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.
π@cveNotify
GitHub
GitHub - huclilu/CVE_Add
Contribute to huclilu/CVE_Add development by creating an account on GitHub.
π¨ CVE-2022-43121
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
π@cveNotify
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
π@cveNotify
GitHub
Cross Site Scripting (XSS) in Members Add Β· Issue #895 Β· intelliants/subrion
Describe the bug Cross Site Scripting (XSS) in the fiekd tooltip section of the members add page. version: 4.2.1 To Reproduce Steps to reproduce the behavior: Go to 'CMS Field Add page&...
π¨ CVE-2022-39956
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity version (v2.9.6 / v3.0.8).
π@cveNotify
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity version (v2.9.6 / v3.0.8).
π@cveNotify
CRS Project
CRS Version 3.3.3 and 3.2.2 (covering several CVEs)
Release announcement covering fixes for CVE-2022-39955, CVE-2022-39956, CVE-2022-39957 and CVE-2022-39958, additional security fixes and security fixes in the latest ModSecurity releases 2.9.6 and 3.0.8.
The OWASP ModSecurity Core Rule Set (CRS) team is pleasedβ¦
The OWASP ModSecurity Core Rule Set (CRS) team is pleasedβ¦
π¨ CVE-2022-39955
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Content-Type header "charset" allow list. An encoded payload can bypass CRS detection this way and may then be decoded by the backend. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
π@cveNotify
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Content-Type header "charset" allow list. An encoded payload can bypass CRS detection this way and may then be decoded by the backend. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
π@cveNotify
CRS Project
CRS Version 3.3.3 and 3.2.2 (covering several CVEs)
Release announcement covering fixes for CVE-2022-39955, CVE-2022-39956, CVE-2022-39957 and CVE-2022-39958, additional security fixes and security fixes in the latest ModSecurity releases 2.9.6 and 3.0.8.
The OWASP ModSecurity Core Rule Set (CRS) team is pleasedβ¦
The OWASP ModSecurity Core Rule Set (CRS) team is pleasedβ¦
π¨ CVE-2021-42205
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.
π@cveNotify
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.
π@cveNotify
π¨ CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-41103.
π@cveNotify
Microsoft Word Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-41103.
π@cveNotify
π¨ CVE-2022-41058
Windows Network Address Translation (NAT) Denial of Service Vulnerability.
π@cveNotify
Windows Network Address Translation (NAT) Denial of Service Vulnerability.
π@cveNotify
π¨ CVE-2022-41056
Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability.
π@cveNotify
Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability.
π@cveNotify