3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-0650
Visitor Management System Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file dataset.php of the component URL Handler. The manipulation of the argument name with the input "><script>alert('torada')</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251376.

CVE-2024-3377
Computer Laboratory Management System Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259498 is the identifier assigned to this vulnerability.

CVE-2024-8157
Alphabetical List Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-34223
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

CVE-2024-6925
TrueBooker Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-12280
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

CVE-2024-3142
E10 Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-258917 was assigned to this vulnerability.

CVE-2024-2822
DedeCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the argument aid leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257709 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-10480
3DPrint Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-3143
DedeCMS Web
4.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/member_rank.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258918 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-9756
Order Attachments for WooCommerce Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-862 1 PoC

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

CVE-2024-1279
Paid Memberships Pro Web Windows
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2024-1564
wp-schema-pro Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

CVE-2024-2908
Call Now Button Web Windows
4.3
MEDIUM
EPSS
2.5%
2024 1 PoC

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4183
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2024 CWE-400 1 PoC

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.

CVE-2024-21517
opencart/opencart Web
4.2
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker can inject arbitrary HTML and Javascript into the page response. As this vulnerability is present in the account functionality it could be used to target and attack customers of the OpenCart shop. **Notes:** 1) The fix for this vulnerability is incomplete

CVE-2024-10815
PostLists Web Windows
4.2
MEDIUM
EPSS
0.2%
2024 1 PoC

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-21515
opencart/opencart Web
4.2
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route. An attacker could obtain a user's token by tricking the user to click on a maliciously crafted URL. The user is then prompted to login and redirected again upon authentication with the payload automatically executing. If the attacked user has admin privileges, this vulnerability could be used as the start of a chain of exploits like Zip Slip or arbitrary file write vulnerabilities in the admin functionality. **Notes:** 1) This is onl

CVE-2024-21516
opencart/opencart Web
4.2
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admin common/filemanager.list route. An attacker could obtain a user's token by tricking the user to click on a maliciously crafted URL. The user is then prompted to login and redirected again upon authentication with the payload automatically executing. If the attacked user has admin privileges, this vulnerability could be used as the start of a chain of exploits like Zip Slip or arbitrary file write vulnerabilities in the admin functionali