CVE-2022-43265 An upload vulnerability in the Canteen Management System v1.0 component /pages/save_user.php allows attackers to execute arbitrary code.
The component receives user-supplied input in the POST request’s file parameter, which is not validated. In addition, the component processes this input as
CVE-2022-3997 - Critical SQL Injection in MonikaBrzica SCM (`upis_u_bazu.php`) — Technical Deep Dive
In late 2022, a critical vulnerability surfaced in MonikaBrzica’s Supply Chain Management (SCM) solution, tracked as CVE-2022-3997 and also referenced as VDB-
CVE-2022-42978 - How a Small Authorization Bug in Netic User Export for Confluence Leads to Unauthenticated File Access
Software security bugs are everywhere, but few are as surprising as those that let random users read files they shouldn’t be able to see.
CVE-2022-42977 - How a Simple Export Feature in Netic User Export Let Attackers Download Any File from Atlassian Confluence
Confluence is one of the most widely-used platforms for team collaboration, and add-ons are often required for various business needs. But sometimes, these
CVE-2022-42984 The offset parameter of the WoW Wonder social network platform was found to be vulnerable to SQL injection.
A successful attack can allow hackers to inject malicious code in the database of the affected website, allowing them to hijack, corrupt, or delete data;
Episode
00:00:00
00:00:00