|
200651
|
8.8 |
HIGH
Network
|
plone
|
plone
|
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
|
CWE-611
XXE
|
CVE-2020-28736
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200652
|
8.8 |
HIGH
Network
|
plone
|
plone
|
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28735
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200653
|
8.8 |
HIGH
Network
|
plone
|
plone
|
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
|
CWE-611
XXE
|
CVE-2020-28734
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200654
|
5.4 |
MEDIUM
Network
|
wondercms
|
wondercms
|
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29233
|
2024-11-21 14:23 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200655
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29245
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200656
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29244
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200657
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29243
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200658
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29242
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200659
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
|
CWE-862
Missing Authorization
|
CVE-2020-29160
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200660
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
|
NVD-CWE-noinfo
|
CVE-2020-29159
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|