Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

GHSA-4q66-g4mm-8rg5: Silverstripe has Cross-site Scripting (XSS) vulnerabilities inherited from TinyMCE

TinyMCE 4.x is vulnerable to several XSS vectors, which had been patched in later versions. Two of these have been identified as affecting `silverstripe/admin`. Only Silverstripe CMS 4 is affected by this issue. It's not possible to upgrade Silverstripe CMS 4 to use a more recent release of TinyMCE without introducing breaking changes. Instead, the security patches that shipped in later releases of TinyMCE have been backported to the TinyMCE version bundled in `silverstripe/admin`. Silverstripe CMS 5 is not affected by those vulnerabilities because it uses TinyMCE 6. You can find more information about the underlying vulnerabilities in those GitHub security advisories: - [GHSA-5h9g-x5rv-25wg Cross-site scripting vulnerability in TinyMCE](https://github.com/advisories/GHSA-5h9g-x5rv-25wg) - [GHSA-w7jx-j77m-wp65 Cross-site scripting vulnerability in TinyMCE](https://github.com/advisories/GHSA-w7jx-j77m-wp65)

ghsa
#xss#vulnerability#git
Joomla iProperty Real Estate 4.1.1 Cross Site Scripting

Joomla iProperty Real Estate extension version 4.1.1 suffers from a cross site scripting vulnerability.

Copyparty 1.8.6 Cross Site Scripting

Copyparty version 1.8.6 suffers from a cross site scripting vulnerability.

CMSninesol 1.0 Cross Site Scripting

CMSninesol version 1.0 suffers from a cross site scripting vulnerability.

CVE-2023-35792: CVE-2023-35792 - Excellium Services

Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS).

CVE-2023-38303: Webmin-2.021/CVE-2023-38303 at main · jaysharma786/Webmin-2.021

An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through the Users and Group's real name parameter.

CVE-2023-38307: Webmin-2.021/CVE-2023-38307 at main · jaysharma786/Webmin-2.021

An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality. The vulnerability occurs when an authenticated user adds a new user and inserts an XSS payload into the user's real name.

CVE-2023-38308: Webmin-2.021/CVE-2023-38308 at main · jaysharma786/Webmin-2.021

An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel functionality when handling third-party domain URLs. By providing a crafted URL from a third-party domain, an attacker can inject malicious code. leading to the execution of arbitrary JavaScript code within the context of the victim's browser.

CVE-2023-38306: Webmin-2.021/CVE-2023-38306 at main · jaysharma786/Webmin-2.021

An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.