Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-3055: Page Builder by AZEXO <= 1.27.133 - Cross-Site Request Forgery to Stored Cross-Site Scripting via azh_save — Wordfence Intelligence

The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_save' function. This makes it possible for unauthenticated attackers to update the post content and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE
#xss#vulnerability#java#wordpress#intel#perl#auth
CVE-2023-33761: CVEs/CVE-2023-33761 at main · rauschecker/CVEs

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php.

CVE-2023-33763: CVEs/CVE-2023-33763 at main · rauschecker/CVEs

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php.

CVE-2023-3074

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-3071: sec(Picklist) sanitize picklist values · tsolucio/corebos@5e87fbc

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-3070

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-3067: fix sanitization of autocomplete against XSS · zadam/trilium@4c3fcc3

Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.

CVE-2023-3060: CveHub/agricultural school management system has cross-site script vulnerability.pdf at main · hotencode/CveHub

A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as problematic. This vulnerability affects the function doAddQuestion of the file btn_functions.php. The manipulation of the argument Question leads to cross site scripting. The attack can be initiated remotely. VDB-230566 is the identifier assigned to this vulnerability.

CVE-2023-3058: 用户信息中存在XSS注入漏洞 · Issue #I76K4N · 零起飞/07FLYCRM客户关系管理系统 - Gitee.com

A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.