|
210831
|
9.3 |
CRITICAL
Network
|
glpi-project fedoraproject
|
glpi fedora
|
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values.…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11035
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210832
|
6.1 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
|
CWE-601
Open Redirect
|
CVE-2020-11034
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210833
|
7.2 |
HIGH
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.
|
CWE-89
SQL Injection
|
CVE-2020-11032
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210834
|
6.5 |
MEDIUM
Network
|
zohocorp
|
manageengine_desktop_central
|
Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
|
CWE-22
Path Traversal
|
CVE-2020-10859
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210835
|
7.2 |
HIGH
Network
|
glpi-project fedoraproject
|
glpi fedora
|
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All ap…
|
CWE-200
Information Exposure
|
CVE-2020-11033
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210836
|
4.8 |
MEDIUM
Network
|
requarks
|
wiki.js
|
In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the Markdown editor, could inject an XSS payload into the content. If another edit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11051
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210837
|
5.3 |
MEDIUM
Network
|
ruby-lang fedoraproject debian
|
ruby fedora debian_linux
|
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buff…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-10933
|
2024-11-21 13:56 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210838
|
7.5 |
HIGH
Network
|
oklok_project
|
oklok
|
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwor…
|
CWE-613 CWE-307
Insufficient Session Expiration mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-10876
|
2024-11-21 13:56 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210839
|
4.7 |
MEDIUM
Local
|
torchbox
|
wagtail
|
In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password …
|
CWE-362
Race Condition
|
CVE-2020-11037
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210840
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11030
|
2024-11-21 13:56 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|