7.1
CVE-2024-47654 - No Rate Limiting vulnerability
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead tβ¦
7.1
CVE-2024-47653 - Missing Authorization Vulnerability
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthoβ¦
5.1
CVE-2024-9481 - Out of Bounds write on scan of malformed eml file may crash the application
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.
7.6
CVE-2024-47652 - Insecure Authentication Vulnerability
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile nuβ¦
7.1
CVE-2024-47651 - Parameter Pollution Vulnerability
This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple βuseridβ parameters in the API request body leading to unauthorized access of sensitive iβ¦
8.2
CVE-2024-6400 - Cleartext Storage of Username and Password in Finrota's Netahsilat
Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versiβ¦
6.4
CVE-2024-9271 - Re:WP <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject β¦
6.4
CVE-2024-9071 - Easy Demo Importer β A Modern One-Click Demo Import Solution <= 1.1.2 - Authenticated (Author+) Stoβ¦
The Easy Demo Importer β A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atβ¦
6.1
CVE-2024-9435 - ShiftController Employee Shift Scheduling <= 4.9.66 - Reflected Cross-Site Scripting
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbβ¦
4.4
CVE-2024-9306 - WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissionβ¦