Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

Google Roulette: Developer console trick can trigger XSS in Chromium browsers

A case study on the complexity of browser security

PortSwigger
#xss#csrf#vulnerability#web#ios#google#java#chrome
CVE-2022-36432: GitHub - afine-com/CVE-2022-36432: Cross-site Scripting (XSS) in Preview functionality in Amasty Blog Pro for Magento 2

The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.

CVE-2022-39834: Keyfactor Support

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

CVE-2022-42954: Keyfactor Support

Keyfactor EJBCA before 7.10.0 allows XSS.

CVE-2022-42985: mediawiki-scratch-login/ScratchLogin.common.php at 4d2c1229b558b9cd685961274f20b621d114f4db · InternationalScratchWiki/mediawiki-scratch-login

The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).

CVE-2022-42960: New Vulnerability in Popular Widget Shows Risks of Third-Party Code | Imperva

EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.

GHSA-r9xx-4cmv-856x: Cross-site Scripting in Zenario

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.

GHSA-j43m-4pxc-hmqj: Cross-site Scripting in Zenario

Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.

GHSA-gmf5-q34v-vwvp: Cross-site Scripting in Zenario

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.