Autore: Angelo Barbosa

CVE-2023-48880 | EyouCMS 1.6.4-UTF8-SP1 login.php Menu Name cross site scripting (Issue 52)

A vulnerability has been found in EyouCMS 1.6.4-UTF8-SP1 and classified as problematic. This vulnerability affects unknown code of the file /login.php?m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn. The manipulation of the argument Menu Name leads to cross site scripting. This vulnerability was named CVE-2023-48880. The attack can be initiated remotely. There is no exploit...

Per saperne di più

CVE-2023-6218 | Progress MOVEit Transfer up to 14.0.8/14.1.9/15.0.6 privileges management

A vulnerability, which was classified as critical, was found in Progress MOVEit Transfer up to 14.0.8/14.1.9/15.0.6. This affects an unknown part. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2023-6218. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49090 | CarrierWave up to 2.2.4/3.0.4 cross site scripting (GHSA-gxhx-g4fq-49hj)

A vulnerability, which was classified as problematic, has been found in CarrierWave up to 2.2.4/3.0.4. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2023-49090. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49652 | Google Compute Engine Plugin 4.550.vb_327fca_3db_11 on Jenkins permission

A vulnerability classified as problematic was found in Google Compute Engine Plugin 4.550.vb_327fca_3db_11 on Jenkins. Affected by this vulnerability is an unknown functionality. The manipulation leads to permission issues. This vulnerability is known as CVE-2023-49652. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più