CVE-2022-4250 The vulnerability of the file booking.php is a problem because the id argument is manipulated by cross site scripting.
The attacker may exploit the application by injecting malicious code to execute malicious actions. The access to the targeted system would be possible by manipulating
CVE-2022-1911 - How a Parser Error in M-Files Server Exposed OS Info — Full Exploit Breakdown
M-Files Server is widely used for document management, storing sensitive files for everything from law firms to government agencies. Imagine if someone could peek
CVE-2022-1606 In M-Files Server versions before 22.3.11164.0 and 22.3.11237.1, user can read unmanaged objects if privilege assignment is incorrect.
This vulnerability allows users with the "Grant Access" privilege to read any data stored in the M-Files database.
M-Files Server versions
CVE-2022-38802 - Exploiting Incorrect Access Control in ZKTeco BioTime (<8.5.3 Build:20200816.447) for Local File Disclosure via XSS-to-PDF
ZKTeco's BioTime is a popular biometric time and attendance management software, used by enterprises worldwide. Security researchers discovered that versions below 8.5.
CVE-2022-3859 An uncontrolled search path vulnerability exists in versions of Trellix Agent prior to 5.7.8. An attacker can exploit this vulnerability to access files on the system.
An attacker can also inject a different DLL than the one configured to be searched for. For example, an attacker may place a malicious DLL
Episode
00:00:00
00:00:00