Aggregator
捷克移动用户成为新银行凭证盗窃计划的目标
2 months 3 weeks ago
安全客
XCon2024完整版参会攻略,速速来看,果断收藏~~
2 months 3 weeks ago
距离XCon2024安全焦点信息安全技术峰会正式开幕仅剩1天
后台仍在不断激增的购票数量
也足见各位对本届XCon的热切期待~~
那今天小编就作为大会的前站路透官
为各位盘上一波XCon2024参会攻略~~
XCon组委会
CVE-2024-7998 | Octopus Server prior 2024.1.12931/2024.2.9313 OIDC Cookie session expiration
2 months 3 weeks ago
A vulnerability was found in Octopus Server. It has been rated as problematic. This issue affects some unknown processing of the component OIDC Cookie Handler. The manipulation leads to session expiration.
The identification of this vulnerability is CVE-2024-7998. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7795 | Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum stack-based overflow (ZDI-24-1154)
2 months 3 weeks ago
A vulnerability was found in Autel MaxiCharger AC Elite Business C50. It has been declared as critical. This vulnerability affects the function AppAuthenExchangeRandomNum. The manipulation leads to stack-based buffer overflow.
This vulnerability was named CVE-2024-7795. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43440 | Moodle Block Backup Restore file inclusion
2 months 3 weeks ago
A vulnerability was found in Moodle. It has been classified as critical. This affects an unknown part of the component Block Backup Restore. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-43440. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43439 | Moodle H5P Error Message cross site scripting
2 months 3 weeks ago
A vulnerability was found in Moodle and classified as problematic. Affected by this issue is some unknown functionality of the component H5P Error Message Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-43439. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43438 | Moodle Feedback Non-Respondents Report resource injection
2 months 3 weeks ago
A vulnerability has been found in Moodle and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Feedback Non-Respondents Report. The manipulation leads to improper control of resource identifiers.
This vulnerability is known as CVE-2024-43438. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43437 | Moodle Backup File Restore cross site scripting
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Moodle. Affected is an unknown function of the component Backup File Restore. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-43437. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43436 | Moodle XMLDB Editor sql injection
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Moodle. This issue affects some unknown processing of the component XMLDB Editor. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-43436. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-43435 | Moodle Global Glossary improper authorization
2 months 3 weeks ago
A vulnerability classified as problematic was found in Moodle. This vulnerability affects unknown code of the component Global Glossary Handler. The manipulation leads to improper authorization.
This vulnerability was named CVE-2024-43435. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43434 | Moodle Feedback Non-Respondents Report cross-site request forgery
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Moodle. This affects an unknown part of the component Feedback Non-Respondents Report. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-43434. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43433 | Moodle Matrix Privilege Escalation
2 months 3 weeks ago
A vulnerability was found in Moodle. It has been rated as critical. Affected by this issue is some unknown functionality of the component Matrix. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-43433. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43432 | Moodle Authorization Header Privilege Escalation
2 months 3 weeks ago
A vulnerability was found in Moodle. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Authorization Header Handler. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-43432. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-43431 | Moodle Badge resource injection
2 months 3 weeks ago
A vulnerability was found in Moodle. It has been classified as problematic. Affected is an unknown function of the component Badge Handler. The manipulation leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2024-43431. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-43430 | Moodle Quiz access control
2 months 3 weeks ago
A vulnerability was found in Moodle and classified as critical. This issue affects some unknown processing of the component Quiz Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-43430. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-43428 | Moodle Storage injection
2 months 3 weeks ago
A vulnerability has been found in Moodle and classified as problematic. This vulnerability affects unknown code of the component Storage Handler. The manipulation leads to injection.
This vulnerability was named CVE-2024-43428. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-43426 | Moodle pdfTeX information disclosure
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Moodle. This affects an unknown part of the component pdfTeX. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-43426. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43425 | Moodle Question Type Privilege Escalation
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Moodle. Affected by this issue is some unknown functionality of the component Question Type Handler. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-43425. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-49198 | Apache SeaTunnel Web 1.0.0 MySQL URL path traversal
2 months 3 weeks ago
A vulnerability classified as critical was found in Apache SeaTunnel Web 1.0.0. Affected by this vulnerability is an unknown functionality of the component MySQL URL Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2023-49198. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com