|
210621
|
7.5 |
HIGH
Network
|
socket.io-file_project
|
socket.io-file
|
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir an…
|
CWE-22
Path Traversal
|
CVE-2020-15779
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210622
|
6.1 |
MEDIUM
Network
|
rosariosis
|
rosariosis
|
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inac…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15718
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210623
|
6.1 |
MEDIUM
Network
|
rosariosis
|
rosariosis
|
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15717
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210624
|
6.1 |
MEDIUM
Network
|
rosariosis
|
rosariosis
|
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15716
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210625
|
6.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2020-15700
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210626
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-15699
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210627
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
|
NVD-CWE-noinfo
|
CVE-2020-15698
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210628
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15697
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210629
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15696
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210630
|
6.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2020-15695
|
2024-11-21 14:06 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|