|
197121
|
4.3 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access…
|
CWE-200
Information Exposure
|
CVE-2020-9386
|
2024-11-21 14:40 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197122
|
6.5 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing port…
|
CWE-200
Information Exposure
|
CVE-2020-9282
|
2024-11-21 14:40 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197123
|
7.8 |
HIGH
Local
|
wftpserver
|
wing_ftp_server
|
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin d…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-9470
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197124
|
6.1 |
MEDIUM
Network
|
ckeditor fedoraproject drupal oracle
|
ckeditor fedora drupal peoplesoft_enterprise_peopletools webcenter_portal agile_plm application_express jd_edwards_enterpriseone_tools siebel_apps_-_customer_order_management<…
|
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9281
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197125
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_…
|
CWE-862
Missing Authorization
|
CVE-2020-9458
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197126
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_set…
|
CWE-862
Missing Authorization
|
CVE-2020-9457
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197127
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_r…
|
CWE-862
Missing Authorization
|
CVE-2020-9456
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197128
|
4.3 |
MEDIUM
Network
|
metagauss
|
registrationmagic
|
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php se…
|
CWE-862
Missing Authorization
|
CVE-2020-9455
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197129
|
8.8 |
HIGH
Network
|
metagauss
|
registrationmagic
|
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, i…
|
CWE-352
Origin Validation Error
|
CVE-2020-9454
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197130
|
6.5 |
MEDIUM
Network
|
mi
|
miui_firmware
|
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of opening other components. Attackers need to induc…
|
CWE-94
Code Injection
|
CVE-2020-9530
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|