|
209611
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has PageController stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12704
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209612
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has XSS during PackageController uninstall.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12703
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209613
|
6.1 |
MEDIUM
Network
|
mitel
|
shoretel_conference_web mivoice_connect
|
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12679
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209614
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12687
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209615
|
5.4 |
MEDIUM
Network
|
katyshop2_project
|
katyshop2
|
Katyshop2 before 2.12 has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12683
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209616
|
6.1 |
MEDIUM
Network
|
iframe_project
|
iframe
|
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12696
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209617
|
5.4 |
MEDIUM
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
|
CWE-347 CWE-294
Improper Verification of Cryptographic Signature Authentication Bypass by Capture-replay
|
CVE-2020-12692
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209618
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
|
CWE-863
Incorrect Authorization
|
CVE-2020-12691
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209619
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a key…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-12690
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209620
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12689
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|