Author: Angelo Barbosa

CVE-2023-6442 | PHPGurukul Nipah Virus Testing Management System 1.0 add-phlebotomist.php empid/fullname cross site scripting

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. This vulnerability is known as CVE-2023-6442. The attack can be launched remotely. Furthermore, there is an exploit...

Read More

CVE-2023-6071 | Trellix Enterprise Security Manager up to 11.6.8 New Data Source command injection (SB10413)

A vulnerability was found in Trellix Enterprise Security Manager up to 11.6.8. It has been classified as critical. Affected is an unknown function of the component New Data Source Handler. The manipulation leads to command injection. This vulnerability is traded as CVE-2023-6071. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-6440 | SourceCodester Book Borrower System 1.0 endpoint/add-book.php Book Title/Book Author cross site scripting

A vulnerability was found in SourceCodester Book Borrower System 1.0 and classified as problematic. This issue affects some unknown processing of the file endpoint/add-book.php. The manipulation of the argument Book Title/Book Author leads to cross site scripting. The identification of this vulnerability is CVE-2023-6440. The attack may be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2023-41127 | Evergreen Content Poster Auto Post and Schedule Your Best Content to Social Media Plugin cross site scripting

A vulnerability has been found in Evergreen Content Poster Auto Post and Schedule Your Best Content to Social Media Plugin up to 1.3.6.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2023-41127. The attack can be initiated remotely. There is no exploit...

Read More