CVE-2022-41588 The home screen module has a vulnerability in its service logic processing. Successful exploitation of this may affect data integrity.
The issue is related to the handling of responses by the application when certain parameters are provided in the request.
An attacker can exploit the
CVE-2022-41539 Wedding Planner v1.0 had an arbitrary file upload vulnerability in the /admin/users_add.php component.
To exploit this issue, an attacker needs to upload a malicious PHP file to the server. After the file is uploaded, an attacker can request
CVE-2022-41538 The Wedding Planner v1.0 had an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php.
This issue can be exploited by uploading a file with a malicious extension. An attacker can upload a PHP file with a file path like
CVE-2022-39297 MelisCms is a CMS for Melis Platform, including templating system, plugins drag and drop, and SEO tools.
This restriction prevents attackers from deserializing user-controlled data and executing arbitrary PHP code on the system. Melis CMS is not enabled by default on
CVE-2022-41350 ZCS 8.8.15 has a vulnerability to Reflected XSS with the phone parameter of /h/search.
The /h/search?phone=&action=listen request can be used to exploit the following scenario: An attacker sends a victim a message with a
Episode
00:00:00
00:00:00