
A verb used in Orion was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.Read More ...

Continue Reading

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).Read More ...

Continue Reading

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.Read More ...

Continue Reading

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. ...

Continue Reading

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.Read More ...

Continue Reading

A limited SQL injection risk was identified in the "browse list of users" site administration page.Read More ...

Continue Reading

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application ...

Continue Reading

AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint valida ...

Continue Reading

Back to Main

Subscribe for the latest news: