Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-39524: Merge remote-tracking branch 'ghsa-75p5-jwx4-qw9h/fix-advisory-1' int… · PrestaShop/PrestaShop@2047d4c

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

CVE
#sql#vulnerability#web#git#php
CVE-2023-4200: Inventory-Management-System/SQL Injection in product_data.php/vuln.md at main · Yesec/Inventory-Management-System

A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file product_data.php.. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-236290 is the identifier assigned to this vulnerability.

CVE-2023-4199

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236289 was assigned to this vulnerability.

CVE-2023-38044: Joomla.org

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-34477: Online Virtual Classroom - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-23758: Creative Gallery - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-34476: Proforms Basic - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-23757: BA Gallery - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Social-Commerce 3.1.6 Cross Site Scripting

Social-Commerce version 3.1.6 suffers from a cross site scripting vulnerability.

mooSocial 3.1.8 Cross Site Scripting

mooSocial version 3.1.8 suffers from a cross site scripting vulnerability.