5.1

CVSS4.0

CVE-2024-49707 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for resetting user's password with a malicious script, what causes the script to run in user's context.  This vulnerabi…

📅 Published: April 14, 2025, 12:06 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:09 p.m.

5.1

CVSS4.0

CVE-2024-49706 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:10 p.m.

5.3

CVSS4.0

CVE-2024-49705 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not be accepted as the server returns an error messa…

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-13598 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. Using a functionality of creating new form fields one creates new parameters vulnerable to XSS attacks. A user tricked into filling such a form with a malicious script will run t…

📅 Published: April 14, 2025, 12:05 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-13597 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form sent to login panel at /softcom/ with a malicious script, what causes the script to run in user's context.  This vulnerability h…

📅 Published: April 14, 2025, 12:04 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2024-10090 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for adding users with a malicious script, what causes the script to run in user's context.  This vulnerability has been…

📅 Published: April 14, 2025, 12:04 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-10089 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for changing user's data with a malicious script, what causes the script to run in user's context.  This vulnerability has…

📅 Published: April 14, 2025, 12:03 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:12 p.m.

5.1

CVSS4.0

CVE-2024-10088 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a login form with a malicious script, what causes the script to run in user's context.  This vulnerability has been patched in version …

📅 Published: April 14, 2025, 12:03 p.m. 🔄 Last Modified: Oct. 28, 2025, 5:12 p.m.

5.3

CVSS4.0

CVE-2024-10087 - XSS in iKSORIS

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might craft a link containing a malicious script, which then gets directly embedded in references to other resources, what causes the script to run in user's context m…

📅 Published: April 14, 2025, 12:03 p.m. 🔄 Last Modified: Oct. 28, 2025, 4:52 p.m.

5.1

CVSS4.0

CVE-2025-3565 - huanfenz/code-projects StudentManager Announcement Management Section uploadArticle.do unrestricted…

A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument File leads to unrestricted upload. The attac…

📅 Published: April 14, 2025, noon 🔄 Last Modified: May 21, 2025, 7:58 p.m.
Total resulsts: 345369
Page 5512 of 34,537
« previous page » next page
Filters