Aggregator
【安全圈】福建警方破获一起侵犯公民个人信息案
2 months 3 weeks ago
【安全圈】某通信公司职员盗用 3400 余户家庭宽带账户、私搭基站贩售流量获刑
2 months 3 weeks ago
【安全圈】Steam 崩了!《黑神话:悟空》的天命人们突遇“第八十二难”
2 months 3 weeks ago
Биткоин на грани квантового переворота
2 months 3 weeks ago
Эксперты предрекают радикальные изменения в индустрии.
CVE-2024-8155 | ContiNew Admin 3.2.0 tree sort sql injection
2 months 3 weeks ago
A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseController#tree of the file /api/system/dept/tree?sort=parentId%2Casc&sort=sort%2Casc. The manipulation of the argument sort leads to sql injection.
This vulnerability is known as CVE-2024-8155. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-8154 | SourceCodester QR Code Bookmark System 1.0 Parameter update-bookmark.php tbl_bookmark_id/name/url cross site scripting
2 months 3 weeks ago
A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_bookmark_id/name/url leads to cross site scripting.
This vulnerability is traded as CVE-2024-8154. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8153 | SourceCodester QR Code Bookmark System 1.0 delete-bookmark.php bookmark cross site scripting
2 months 3 weeks ago
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8153. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8152 | SourceCodester QR Code Bookmark System 1.0 Parameter add-bookmark.php name/url cross site scripting
2 months 3 weeks ago
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argument name/url leads to cross site scripting.
This vulnerability was named CVE-2024-8152. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8151 | SourceCodester Interactive Map with Marker 1.0 delete-mark.php mark cross site scripting
2 months 3 weeks ago
A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8151. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #391851: https://github.com/continew-org/continew-admin ContiNew Admin 3.2.0 SQL Injection [Accepted]
2 months 3 weeks ago
Submit #391851 / VDB-275743
Chiexf
Submit #397580: SourceCodester QR Code Bookmark System 1.0 Cross Site Scripting [Accepted]
2 months 3 weeks ago
Submit #397580 / VDB-275742
jadu101
Submit #397579: SourceCodester QR Code Bookmark System 1.0 Cross Site Scripting [Accepted]
2 months 3 weeks ago
Submit #397579 / VDB-275741
jadu101
Submit #397575: SourceCodester QR Code Bookmark System 1.0 Cross Site Scripting [Accepted]
2 months 3 weeks ago
Submit #397575 / VDB-275740
jadu101
CVE-2024-8150 | ContiNew Admin 3.2.0 user sort sql injection
2 months 3 weeks ago
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation of the argument sort leads to sql injection.
This vulnerability is handled as CVE-2024-8150. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #397570: SourceCodester Interactive Map with Marker 1.0 Cross Site Scripting [Accepted]
2 months 3 weeks ago
Submit #397570 / VDB-275739
jadu101
CVE-2024-45244 | Hyperledger Fabric up to 2.5.9 Timestamp Privilege Escalation
2 months 3 weeks ago
A vulnerability has been found in Hyperledger Fabric up to 2.5.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Timestamp Handler. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-45244. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-45240 | TikTok App up to 34.5.4 on Android Lynxview JavaScript Interface
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in TikTok App up to 34.5.4 on Android. Affected is an unknown function of the component Lynxview JavaScript Interface. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2024-45240. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45239 | NICMx Fort up to 1.6.2 eContent null pointer dereference
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in NICMx Fort up to 1.6.2. This issue affects some unknown processing. The manipulation of the argument eContent leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-45239. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45236 | NICMx Fort up to 1.6.2 Signed Object signedAttributes denial of service
2 months 3 weeks ago
A vulnerability classified as problematic was found in NICMx Fort up to 1.6.2. This vulnerability affects unknown code of the component Signed Object Handler. The manipulation of the argument signedAttributes leads to denial of service.
This vulnerability was named CVE-2024-45236. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com