5.1

CVSS4.0

CVE-2025-3568 - Webkul Krayin CRM SVG File edit cross site scripting

A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be laun…

📅 Published: April 14, 2025, 1:31 p.m. 🔄 Last Modified: June 26, 2025, 7:21 p.m.

5.3

CVSS4.0

CVE-2025-3567 - veal98 小牛肉 Echo 开源社区系统 Ticket LoginTicketInterceptor.java preHandle improper authorization

A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function preHandle of the file src/main/java/com/greate/community/controller/interceptor/LoginTicketInterceptor.java of the component Ticket Handler. The manipulation leads to improper aut…

📅 Published: April 14, 2025, 1 p.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.

6.9

CVSS4.0

CVE-2025-3566 - veal98 小牛肉 Echo 开源社区系统 uploadMdPic unrestricted upload

A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-image-file leads to unrestricted upload. The attack may be initiated remotely. The…

📅 Published: April 14, 2025, 12:31 p.m. 🔄 Last Modified: Aug. 26, 2025, 8:15 p.m.

2.3

CVSS4.0

CVE-2024-49709 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attacker with an access to user's browser might set such a cookie, wait until the user logs in and then use the same cookie to take over the account. Moreover, the system does not dest…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:07 p.m.

5.1

CVSS4.0

CVE-2024-49708 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for setting delivery address with a malicious script, what causes the script to run in user's context.  This vulnerability…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:08 p.m.

5.1

CVSS4.0

CVE-2024-49707 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for resetting user's password with a malicious script, what causes the script to run in user's context.  This vulnerabi…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:09 p.m.

5.1

CVSS4.0

CVE-2024-49706 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:10 p.m.

5.3

CVSS4.0

CVE-2024-49705 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not be accepted as the server returns an error messa…

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-13598 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. Using a functionality of creating new form fields one creates new parameters vulnerable to XSS attacks. A user tricked into filling such a form with a malicious script will run t…

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-13597 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form sent to login panel at /softcom/ with a malicious script, what causes the script to run in user's context.  This vulnerability h…

📅 Published: April 14, 2025, 12:04 p.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.
Total resulsts: 343923
Page 5367 of 34,393
« previous page » next page
Filters