π¨ CVE-2022-41208
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.
π@cveNotify
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.
π@cveNotify
π¨ CVE-2022-41205
SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.
π@cveNotify
SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.
π@cveNotify
π¨ CVE-2022-3489
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
π@cveNotify
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
π@cveNotify
Wpscan
WPScan: WordPress Security Scanner
A WordPress vulnerability database for WordPress core security vulnerabilities, plugin vulnerabilities and theme vulnerabilities.
π¨ CVE-2022-41079
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2022-41078.
π@cveNotify
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2022-41078.
π@cveNotify
π¨ CVE-2022-3494
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
π@cveNotify
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
π@cveNotify
WPScan
Complianz (Free < 6.3.4, Premium < 6.3.6) - Translator SQLi
See details on Complianz (Free < 6.3.4, Premium < 6.3.6) - Translator SQLi CVE 2022-3494. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-3558
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
π@cveNotify
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
π@cveNotify
π¨ CVE-2022-41123
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41080.
π@cveNotify
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41080.
π@cveNotify
π¨ CVE-2022-41080
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123.
π@cveNotify
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123.
π@cveNotify
π¨ CVE-2022-41078
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2022-41079.
π@cveNotify
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2022-41079.
π@cveNotify
π¨ CVE-2022-44544
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
π@cveNotify
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
π@cveNotify
Launchpad
Bug #1979575 βVulnerable PDF can trigger remote shell with PDF e...β : Series 22.10 : Bugs : Mahara
The problem is Ubuntu 18.04 servers require the use of the flag -dSAFER with ghostscript, otherwise if you submit a vulnerable PDF you can trigger a remote shell.
In Mahara, ghostscript can be used to combine generated pdfs for pdf export.
As it's not theβ¦
In Mahara, ghostscript can be used to combine generated pdfs for pdf export.
As it's not theβ¦
π¨ CVE-2022-32588
An out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
π@cveNotify
An out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
π@cveNotify
π¨ CVE-2022-3536
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
π@cveNotify
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can upload a file, and a suitable gadget chain is present on the blog
π@cveNotify
WPScan
Role Based Pricing for WooCommerce < 1.6.3 - Subscriber+ PHAR Deserialization
See details on Role Based Pricing for WooCommerce < 1.6.3 - Subscriber+ PHAR Deserialization CVE 2022-3536. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-39398
tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross-site Scripting (XSS) - Create XSS in task content (when add it). This issue is patched in version 2.0.3. There are no known workarounds.
π@cveNotify
tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross-site Scripting (XSS) - Create XSS in task content (when add it). This issue is patched in version 2.0.3. There are no known workarounds.
π@cveNotify
GitHub
Cross-site Scripting (XSS) - Create XSS in task content
### Impact
_What kind of vulnerability is it? Who is impacted?_
Cross-site Scripting (XSS) - Create XSS in task content (when add it)
### Patches
_Has the problem been patched? What versions ...
_What kind of vulnerability is it? Who is impacted?_
Cross-site Scripting (XSS) - Create XSS in task content (when add it)
### Patches
_Has the problem been patched? What versions ...
π¨ CVE-2022-39396
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This issue is patched in version 5.3.1 and in 4.10.18. There are no known workarounds.
π@cveNotify
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This issue is patched in version 5.3.1 and in 4.10.18. There are no known workarounds.
π@cveNotify
GitHub
ZDI-CAN-18358: Remote code execution via MongoDB BSON parser through prototype pollution
### Impact
An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.
### Patches
Prevent prototype pollution in MongoDB databas...
An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.
### Patches
Prevent prototype pollution in MongoDB databas...
π¨ CVE-2022-45130
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.
π@cveNotify
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.
π@cveNotify
FORTBRIDGE
Compromising Plesk via its REST API
Compromising Plesk via its REST API, CSRF, CORS misconfiguration, add db user, add backdoor, add secret token, cookieless CSRF
π¨ CVE-2022-45129
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
π@cveNotify
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
π@cveNotify
GitHub
Merge pull request #5989 from luiseufrasio/FISH-6603 Β· payara/Payara@cccdfdd
Fish-6603 New 0-day vulnerability exploit using ROOT context root deployments
π¨ CVE-2022-3867
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
π@cveNotify
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
π@cveNotify
HashiCorp Discuss
HCSEC-2022-26 - Nomadβs Event Stream Subscriber Using ACL Token with TTL Receive Updates Until Garbage Collected
Bulletin ID: HCSEC-2022-26 Affected Products / Versions: Nomad and Nomad Enterprise 1.4.0 up to 1.4.1; fixed in 1.4.2. Publication Date: October 28, 2022 Summary A vulnerability was identified in Nomad and Nomad Enterprise (βNomadβ) such that an eventβ¦
π¨ CVE-2022-42787
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. An unathenticated remote attacker can brute force the session id and gets access to an account on the the device.
π@cveNotify
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. An unathenticated remote attacker can brute force the session id and gets access to an account on the the device.
π@cveNotify
Certvde
VDE-2022-043 | CERT@VDE
Advisories
π¨ CVE-2022-42786
Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage
π@cveNotify
Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage
π@cveNotify
Certvde
VDE-2022-043 | CERT@VDE
Advisories
π¨ CVE-2022-44547
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
π@cveNotify
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
π@cveNotify
π¨ CVE-2022-44546
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
π@cveNotify
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
π@cveNotify