Autore: Angelo Barbosa

CVE-2023-5955 | Contact Form Email Plugin up to 1.3.43 on WordPress Setting cross site scripting

A vulnerability was found in Contact Form Email Plugin up to 1.3.43 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2023-5955. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49795 | MindsDB up to 23.11.4.0 file.py server-side request forgery (GHSA-34mr-6q8x-g9r6)

A vulnerability was found in MindsDB up to 23.11.4.0 and classified as critical. This issue affects some unknown processing of the file file.py. The manipulation leads to server-side request forgery. The identification of this vulnerability is CVE-2023-49795. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-48715 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross site scripting

A vulnerability, which was classified as problematic, was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2023-48715. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più