2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-27147
TIBCO PartnerExpress Web
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.

CVE-2020-5247
Puma Web
6.5
MEDIUM
EPSS
2.1%
2020 CWE-113 1 PoC

In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2019-16254, which fixed this vulnerability for the WEBrick Ruby web server. This has been fix

CVE-2020-7773
markdown-it-highlightjs Web
6.5
MEDIUM
EPSS
0.4%
2020 1 PoC

This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md = require('markdown-it'); const reuslt_xss = md() .use(markdownItHighlightjs, { inline: true }) .render('console.log(42){.">js}'); console.log(reuslt_xss);

CVE-2020-6134
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the ID parameters of OS4Ed openSIS 7.3 pages. The id parameter in the page MassDropModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6128
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. The meet_date parameter in the page CoursePeriodModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27231
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27240
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6145
ERPNext Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-13525
ProcessMaker Web Database
6.4
MEDIUM
EPSS
1.6%
2020 CWE-89 1 PoC

The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27239
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6136
OS4Ed Web Database
6.4
MEDIUM
EPSS
1.7%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6129
OS4ED Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page CpSessionSet.php is vulnerable to SQL injection.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-13526
ProcessMaker Web Database
6.4
MEDIUM
EPSS
1.6%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27234
OpenClinic Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6122
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The mn parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-6126
OS4Ed Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CoursePeriodModal.php page of OS4Ed openSIS 7.3. The course_period_id parameter in the page CoursePeriodModal.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

CVE-2020-27232
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
1.5%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-27230
OpenClinic GA Web Database
6.4
MEDIUM
EPSS
0.3%
2020 CWE-89 1 PoC

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-15119
lock Web
6.4
MEDIUM
EPSS
0.3%
2020 CWE-79 1 PoC

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

CVE-2020-6117
OS4ED" Web Database
6.4
MEDIUM
EPSS
0.4%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.