Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-35196: CVEs/TestLink/CVE-2022-35196 at main · HuangYuHsiangPhone/CVEs

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVE
#csrf#vulnerability#git#php
Kiwi Farms breached, user data potentially exposed

Categories: News Tags: Kiwifarms Tags: breach Tags: compromise Tags: exposure Tags: forum Tags: forums Kiwi Farms, which gained a reputation for sophisticated trolling and doxxing, has experienced a potentially severe data breach. (Read more...) The post Kiwi Farms breached, user data potentially exposed appeared first on Malwarebytes Labs.

ProcessMaker Privilege Escalation

ProcessMaker versions prior to 3.5.4 were discovered to be susceptible to a remote privilege escalation vulnerability.

CVE-2022-38509: bug_report/SQLi-1.md at main · ptanly/bug_report

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

CVE-2022-28204: Whatlinkshere of heavily used properties in wikidata can be easily utilized as a DDoS vector

A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.

CVE-2022-38576: bug_report/SQLi-1.md at main · gith-boot/bug_report

Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=.

VIAVIWEB Wallpaper Admin SQL Injection / Shell Upload

VIAVIWEB Wallpaper Admin suffers from remote shell upload and remote SQL injection vulnerabilities.

CVE-2022-35914: absent?: ././internal_utilities/htmLawed?cve=title/ | PHP Labware source code viewer

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

CVE-2022-37700: CVE-2022–37700 Directory Transversal in ZenTao Easy soft ALM v16.5

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

CVE-2022-29908

The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.