Author: Angelo Barbosa

CVE-2023-6575 | Beijing Baichuo S210 up to 20231121 HTTP POST Request /Tool/repair.php txt sql injection

A vulnerability was found in Beijing Baichuo S210 up to 20231121. It has been classified as critical. This affects an unknown part of the file /Tool/repair.php of the component HTTP POST Request Handler. The manipulation of the argument txt leads to sql injection. This vulnerability is uniquely identified as CVE-2023-6575. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2023-6574 | Beijing Baichuo Smart S20 up to 20231120 HTTP POST Request /sysmanage/updateos.php 1_file_upload unrestricted upload

A vulnerability was found in Beijing Baichuo Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updateos.php of the component HTTP POST Request Handler. The manipulation of the argument 1_file_upload leads to unrestricted upload. This vulnerability is handled as CVE-2023-6574. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2023-35039 | Be Devious Web Development Password Reset with Code REST API Plugin up to 0.0.15 on WordPress excessive authentication

A vulnerability has been found in Be Devious Web Development Password Reset with Code REST API Plugin up to 0.0.15 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper restriction of excessive authentication attempts. This vulnerability is known as CVE-2023-35039. The attack can be launched remotely. There is no exploit...

Read More