7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6300
Best Courier Management System General
3.5
LOW
EPSS
0.2%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function. The manipulation of the argument page with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246126 is the identifier assigned to this vulnerability.

CVE-2023-3577
Mattermost General
3.5
LOW
EPSS
0.2%
2023 CWE-918 1 PoC

Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.

CVE-2023-4879
instantsoft/icms2 Web
3.5
LOW
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.

CVE-2023-3846
mooDating General ⚡ nuclei
3.5
LOW
EPSS
7.6%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in mooSocial mooDating 1.2. This affects an unknown part of the file /pages of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235197 was assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVE-2023-6473
Online Quiz System Web
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Online Quiz System 1.0. This affects an unknown part of the file take-quiz.php. The manipulation of the argument quiz_taker/year_section leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246639.

CVE-2023-3886
Beauty Salon Management System Web
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/invoice.php. The manipulation of the argument inv_id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235248.

CVE-2023-3790
CMS Web
3.5
LOW
EPSS
0.1%
2023 CWE-79 2 PoCs

A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235057 was assigned to this vulnerability.

CVE-2023-1421
Mattermost Web
3.5
LOW
EPSS
1.7%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.

CVE-2023-5900
pkp/pkp-lib Web
3.5
LOW
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-7132
Intern Membership Management System General
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input "><ScRiPt>confirm(document.domain)</ScRiPt>h0la leads to cross site scripting. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249135.

CVE-2023-4547
eCommerce CMS Web ⚡ nuclei
3.5
LOW
EPSS
9.1%
2023 CWE-79 1 PoC

A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.

CVE-2023-3014
BeipyVideoResolution Web
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. Affected is an unknown function of the file admin/admincore.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230358 is the identifier assigned to this vulnerability.

CVE-2023-3848
mooDating General ⚡ nuclei
3.5
LOW
EPSS
7.6%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2. This issue affects some unknown processing of the file /users/view of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235199. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVE-2023-5578
i-Educar Web
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-242143. NOTE: The vendor was contacted early about this disclosure

CVE-2023-0840
PHPCrazy Web
3.5
LOW
EPSS
0.2%
2023 CWE-79 1 PoC

A vulnerability classified as problematic was found in PHPCrazy 1.1.1. This vulnerability affects unknown code of the file admin/admin.php?action=users&mode=info&user=2. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221086 is the identifier assigned to this vulnerability.

CVE-2023-3830
SASS BILLER General
3.5
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Bug Finder SASS BILLER 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /company/store. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235151. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3787
Tiva Events Calender General
3.5
LOW
EPSS
0.1%
2023 CWE-79 3 PoCs

A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the identifier assigned to this vulnerability.

CVE-2023-4382
Hyip Rio General
3.5
LOW
EPSS
0.4%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. Affected by this issue is some unknown functionality of the file /user/settings of the component Profile Settings. The manipulation of the argument avatar leads to cross site scripting. The attack may be launched remotely. VDB-237314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0563
Bank Locker Management System Web ⚡ nuclei
3.5
LOW
EPSS
32.7%
2023 CWE-79 0 PoCs

A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.

CVE-2023-0902
Simple Food Ordering System Web
3.5
LOW
EPSS
2.7%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file process_order.php. The manipulation of the argument order leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221451.