Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-22951: Unsecured Web Credentials

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.

CVE
#sql#vulnerability#web#linux#nginx#auth#ssh#docker
CVE-2023-27667: CVE-2023-27667

Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

CVE-2023-22950: Data Loading Vulnerability

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.

CVE-2023-27779: alo.com

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

CVE-2023-27812: bloofoxCMS - Home

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

CVE-2023-29598: lmxcms v1.4.1 Front page sql injection · Issue #3 · jspring996/PHPcodecms

lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.

CVE-2023-29597: bloofox 0.5.2 sql injection · Issue #2 · jspring996/PHPcodecms

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

CVE-2023-23591: Release Notes Highlights - Terminalfour Documentation

The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.