Author: Angelo Barbosa

CVE-2023-6648 | PHPGurukul Nipah Virus Testing Management System 1.0 password-recovery.php username sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username leads to sql injection. This vulnerability is uniquely identified as CVE-2023-6648. It is possible to initiate the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2023-6647 | AMTT HiBOS 1.0 Type sql injection

A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unknown functionality. The manipulation of the argument Type leads to sql injection. This vulnerability is handled as CVE-2023-6647. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2023-6646 | linkding 1.23.0 q cross site scripting

A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipulation of the argument q leads to cross site scripting. This vulnerability is traded as CVE-2023-6646. It is possible to launch the attack remotely. Furthermore, there is an exploit available. The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product. It is recommended to upgrade the affected...

Read More

CVE-2023-49798 | OpenZeppelin openzeppelin-contracts 4.9.4 Subcall control flow (GHSA-699g-q6qh-q4v8)

A vulnerability was found in OpenZeppelin openzeppelin-contracts 4.9.4. It has been rated as problematic. This issue affects some unknown processing of the component Subcall Handler. The manipulation leads to incorrect control flow. The identification of this vulnerability is CVE-2023-49798. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More