CVE-2022-38509 Wedding Planner v1.0 had a SQL injection vulnerability where the booking_id parameter was vulnerable.
An attacker can inject malicious SQL code or cause SQL errors in the database via the booking_id parameter. In certain cases, SQL injection can
CVE-2022-2754 The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters, which could allow unauthenticated attackers to perform SQL Injection attacks.
through the WordPress admin interface. An attacker can inject a SQL statement by sending a malicious request to the vulnerable server, then by sending a
CVE-2022-2710 The Scroll To Top WordPress plugin before 1.4.1 has an unfiltered_html setting that allows high privilege users to do Stored Cross-Site Scripting attacks.
The following example shows how a hacker can exploit this to execute arbitrary cross-site scripting attacks: In the above example, the hacker is using
CVE-2022-3231 Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
It has now been patched. Prior to the patch, XSS could be exploited by an attacker to inject malicious scripts into almost any LibreNMS page,
CVE-2022-38621 Fox Doufox CMS was found to have a RCE vulnerability on the edit file page.
An attacker can host a specially crafted PHP file on a Web server and cause the application to consume an excessive amount of CPU resources.
Episode
00:00:00
00:00:00