CVE-2022-37775 Genesys PureConnect Interaction Web Tools Chat Service has XSS in the Printable Chat History via the participant -> name JSON POST parameter.
This injection can be used for issuing a XSS attack to the system users or to other systems if the users are logged in to
CVE-2022-2799 The Affiliates Manager WordPress plugin before 2.9.14 has unsafe settings that allow attackers to do Cross-Site Scripting.
Plugin writers are encouraged to review the settings they have access to to make sure they are only accessible to the WordPress roles that they
CVE-2022-38305 AeroCMS v0.0.1 had an arbitrary file upload vulnerability in the /admin/profile.php component.
To exploit this issue, an attacker must trick a user to upload a file and then access the file via an HTTP request.
AeroCMS v0.
CVE-2022-39146 V33.1-V33.1.262 has a vulnerability. V34.0-V34.1.242 has a vulnerability. V35.0 has no vulnerabilities.
A vulnerability has been identified in the OpenSCADA software. The application does not properly sanitize user-supplied input before using it in a SQL query.
CVE-2022-38303 Leave Management System v1.0 had a SQL injection vulnerability via the id parameter.
An attacker can exploit this to inject PHP code, extract data, or execute arbitrary SQL commands. This is often a vector for hackers to exploit.
Episode
00:00:00
00:00:00