|
210321
|
8.1 |
HIGH
Network
|
microweber
|
microweber
|
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session doe…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-23140
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210322
|
5.5 |
MEDIUM
Local
|
microweber
|
microweber
|
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a compl…
|
CWE-287
Improper Authentication
|
CVE-2020-23139
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210323
|
9.8 |
CRITICAL
Network
|
microweber
|
microweber
|
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23138
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210324
|
5.5 |
MEDIUM
Local
|
microweber
|
microweber
|
Microweber v1.1.18 is affected by no session expiry after log-out.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-23136
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210325
|
9.8 |
CRITICAL
Network
|
jomsocial
|
jomsocial
|
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22274
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210326
|
6.5 |
MEDIUM
Network
|
creativeitem
|
neoflex_video_subscription_system
|
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
|
CWE-352
Origin Validation Error
|
CVE-2020-22273
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210327
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22278
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210328
|
8.0 |
HIGH
Network
|
codection
|
import_and_export_users_and_customers
|
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22277
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210329
|
9.8 |
CRITICAL
Network
|
weformspro
|
weforms
|
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22276
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210330
|
8.8 |
HIGH
Network
|
easyregistrationforms
|
easy_registration_forms
|
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the fo…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22275
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|