CVE-2022-25323 - Exploiting XSS in ZEROF Web Server 2. via /admin.back
Published: June 28, 2024
Severity: Medium
Component: ZEROF Web Server 2.
Vulnerability type: Cross-Site Scripting (XSS)
CVE ID: CVE-2022-25323
Introduction
Security vulnerabilities
CVE-2022-25314 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
This issue has been fixed in version 2.5.0. In other words, make sure to upgrade your installation as soon as it becomes available.
CVE-2022-24665 PHP Code Snippets were included in 2.0.3 of PHP Everywhere, which allowed execution of code snippets by any user able to edit posts.
This functionality was intentionally disabled by the developers of the plugin in order to prevent any possible security issues.
The snipped code could be posted
CVE-2022-24663 PHP Code Snippets can be executed via WordPress shortcodes in PHP Everywhere =2.0.3.
The snipping functionality was disabled by default in PHP 5.3 and 5.4 due to security issues. If you were using PHP 5.3
CVE-2022-23638 - Security Flaw in svg-sanitizer Library Leads to XSS Attacks
svg-sanitizer is a popular PHP library used for cleaning and validating SVG files. It is commonly integrated in web platforms to ensure that uploaded
Episode
00:00:00
00:00:00