CVE-2022-41936 The `modifications` API does not filter entries by user rights.
-XWiki sites using the `modifications` REST endpoints do not filter entries based on the user's rights. This means that information such as comments,
CVE-2022-43707 - Breaking Down the MyBB 1.8.31 XSS Vulnerability in SCEditor
In late 2022, a critical security issue (tracked as CVE-2022-43707) was discovered in MyBB 1.8.31, one of the world’s most
CVE-2022-44787 - Reflected XSS in Appalti & Contratti 9.12.2 (idPagina) — Analysis and Exploit Details
---
Published: June 2024
If you work with e-procurement systems, especially Appalti & Contratti, you should immediately pay attention to CVE-2022-44787. This post
CVE-2022-44786 - Local File Inclusion in Appalti & Contratti 9.12.2 – Full Exploit Guide
In late 2022, a critical security flaw was discovered in the Appalti & Contratti application, version 9.12.2. This vulnerability, tracked as CVE-2022-
CVE-2022-44784 - Remote Arbitrary Service Creation & Code Execution in Appalti & Contratti (LFS / DL229) via Exposed Axis AdminService
In 2022, a critical vulnerability was discovered in Appalti & Contratti version 9.12.2, within its widely used web applications LFS and DL229. The
Episode
00:00:00
00:00:00