Autore: Angelo Barbosa

CVE-2024-1115 | openBI up to 1.0.8 Setting.php dlfile phpPath os command injection

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of the file /application/websocket/controller/Setting.php. The manipulation of the argument phpPath leads to os command injection. The identification of this vulnerability is CVE-2024-1115. The attack may be initiated remotely. Furthermore, there is an exploit...

Per saperne di più

CVE-2024-1114 | openBI up to 1.0.8 Screen.php dlfile fileUrl access control

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php. The manipulation of the argument fileUrl leads to improper access controls. This vulnerability was named CVE-2024-1114. The attack can be initiated remotely. Furthermore, there is an exploit...

Per saperne di più

CVE-2024-1113 | openBI up to 1.0.8 Unity.php uploadUnity file unrestricted upload

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The manipulation of the argument file leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2024-1113. It is possible to initiate the attack remotely. Furthermore, there is an exploit...

Per saperne di più

CVE-2024-1111 | SourceCodester QR Code Login System 1.0 add-user.php qr-code cross site scripting

A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Login System 1.0. Affected by this issue is some unknown functionality of the file add-user.php. The manipulation of the argument qr-code leads to cross site scripting. This vulnerability is handled as CVE-2024-1111. The attack may be launched remotely. Furthermore, there is an exploit...

Per saperne di più

CVE-2024-22304 | Borbis Media FreshMail For WordPress Plugin up to 2.3.2 on WordPress cross-site request forgery

A vulnerability classified as problematic was found in Borbis Media FreshMail For WordPress Plugin up to 2.3.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. This vulnerability is known as CVE-2024-22304. The attack can be launched remotely. There is no exploit...

Per saperne di più