CVE-2022-43691 Concrete CMS 9.0.0 to 9.1.2 have security issues when Debug Mode is on in production.
Server information like the server’s hostname and which version of PHP are running are visible in the debug logs. This information can be used
CVE-2022-43146 An arbitrary file upload vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary code.
Furthermore, arbitrary file deletion, posting, and modification are also possible due to insufficient input sanitization. Attackers can use this vulnerability to upload or delete the
CVE-2022-3992 - Cross-Site Scripting in SourceCodester Sanitization Management System (Banner Image Handler)
In this post, we’ll take a close look at CVE-2022-3992, a security vulnerability found in the SourceCodester Sanitization Management System, specifically affecting
CVE-2022-43288 The v3.2.1 version of the Rukovoditel software contains a SQL injection vulnerability.
A user with the ability to create account can inject arbitrary SQL commands that will be executed once the order_by function is called.
Rukovoditel
CVE-2022-31630 Before 7.4.33, 8.0.25, and 8.2.12, gd extension's imageloadfont() could be used to load a font that would be read outside allocated buffer.
The vulnerable font file can be crafted with font encoding such as greek. An example vulnerability can be found in the function imageloadfont() in file
Episode
00:00:00
00:00:00