** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.Read More ...
Continue ReadingJune 17, 2022
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.Read More ...
Continue ReadingJune 17, 2022
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.Read More ...
Continue ReadingJune 17, 2022
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.Read More ...
Continue ReadingJune 17, 2022
A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to privilege escalation ...
Continue ReadingJune 17, 2022
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.Read More ...
Continue ReadingJune 17, 2022
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.Read More ...
Continue ReadingJune 17, 2022
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.Read More ...
Continue ReadingJune 17, 2022
Back to Main