CVE-2022-41654 The newsletter subscription functionality of Ghost Foundation 5.9.4 can be exploited to gain increased privileges.
Ghost Foundation Ghost 5.9.4 is vulnerable to cross-site request forgery (CSRF) due to insecure usage of HTTP requests. A hacker can easily perform
CVE-2022-3865 The WP User Merger plugin before 1.5.3 does not properly sanitise and escape a parameter, which allows users with a role as low as admin to inject SQL queries.
This can be exploited by attackers to run arbitrary SQL queries as high privileged users. WP user merger is used to reduce the amount of
CVE-2020-23590 The Optilink V2.2 and V3.3.1 OP-XT71000N has a CSRF vulnerability that can be exploited to change the password for the WLAN SSID.
Optilink OP-XT71000N V2.2, Firmware Version: OP_V3.3.1-191028 is vulnerable to a cross-site request forgery (CSRF) vulnerability when an unauthenticated user's session is
CVE-2022-37772 Maarch RM 2.8.3 has an improper restriction of excessive authentication attempts due to excessive verbose responses from the application.
Redirecting users to arbitrary hosts after they have authenticated is dangerous, as this type of attack could be used to serve malicious content or install
CVE-2020-23592 An unauthenticated, remote attacker can conduct a CSRF attack to reset the ONU to factory default.
An attacker can hijack the session of an authenticated user to log-in as a 'root' user and delete files or perform other actions as 'root'
Episode
00:00:00
00:00:00