|
223091
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16978
|
2024-11-21 13:31 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16862
|
2024-11-21 13:31 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
5.4 |
MEDIUM
Network
|
managewp
|
broken_link_checker
|
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17207
|
2024-11-21 13:31 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
7.5 |
HIGH
Network
|
linuxfoundation vmware
|
harbor cloud_foundation harbor_container_registry
|
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permiss…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16919
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
2fa_enterprise_server
|
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_us…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17120
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
8.8 |
HIGH
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17119
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
8.8 |
HIGH
Network
|
wikidsystems
|
2fa_enterprise_server
|
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2…
|
CWE-352
Origin Validation Error
|
CVE-2019-17118
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
8.8 |
HIGH
Network
|
wikidsystems
|
2fa_enterprise_server
|
A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key paramete…
|
CWE-89
SQL Injection
|
CVE-2019-17117
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17116
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17115
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|