Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-83g7-8fch-p37m: PaddlePaddle vulnerable to code injection via winstr

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

ghsa
#git
GHSA-cm7f-hf2g-ghrp: PyroCMS vulnerable to stored Cross Site Scripting

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS) when a low privileged user, such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

GHSA-g389-rf5p-fg56: Badaso vulnerable to Remote Code Execution (RCE)

Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

GHSA-6q49-35h6-rq2p: Browsershot version 3.57.3 vulnerable to improper input validation

Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.

GHSA-79gx-3fm8-qxqq: Microweber vulnerable to cross-site scripting (XSS)

Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. There was a patch released in the development branch but is not yet committed to the main branch.

GHSA-8c2c-jxwj-jqgf: Browsershot does not validate URL protocols passed to Browsershot URL method

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

GHSA-g5cj-5h58-j93w: Jeecg-boot vulnerable to SQL Injection

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

GHSA-4j2x-v3mr-467m: Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

GHSA-v87q-rpwp-qr7q: Jeecg-boot vulnerable to SQL Injection

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.

GHSA-25gv-mvm7-5h3h: Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.