Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-29713: CVE-2023-29713 - Reflected XSS in Vade Secure Gateway

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory.

CVE
#xss#vulnerability#java
GHSA-gq98-53rq-qr5h: Hashicorp Vault vulnerable to Cross-site Scripting

Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI through key values. This vulnerability, CVE-2023-2121, is fixed in Vault 1.14.0, 1.13.3, 1.12.7, and 1.11.11.

CVE-2023-29712: Vade Secure Gateway Multiple XSS (CVE-2023-29712, CVE-2023-29713, CVE-2023-29714)

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter.

Movierocket 1.0 Cross Site Scripting

Movierocket version 1.0 suffers from a cross site scripting vulnerability.

Codemonkey Multi Vendor Digital Product Mart 1.0 Cross Site Scripting

Codemonkey Multi Vendor Digital Product Mart version 1.0 suffers from a cross site scripting vulnerability.

Scriptio 1.4 Cross Site Scripting

Scriptio version 1.4 suffers from a cross site scripting vulnerability.

EasyAnswer 1.0.1 Cross Site Scripting

EasyAnswer version 1.0.1 suffers from a cross site scripting vulnerability.

PHP Live 3.1 Cross Site Scripting

PHP Live version 3.1 suffers from a cross site scripting vulnerability.

CVE-2023-3184

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.