|
224241
|
6.5 |
MEDIUM
Network
|
enghouse
|
web_chat
|
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the us…
|
CWE-20
Improper Input Validation
|
CVE-2019-16949
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224242
|
9.8 |
CRITICAL
Network
|
enghouse
|
web_chat
|
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-16948
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224243
|
8.8 |
HIGH
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-17237
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224244
|
6.1 |
MEDIUM
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17236
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224245
|
5.3 |
MEDIUM
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17235
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224246
|
7.5 |
HIGH
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17234
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224247
|
6.1 |
MEDIUM
Network
|
intelbras
|
wrn_150_firmware
|
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the confi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17222
|
2024-11-21 13:31 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224248
|
5.4 |
MEDIUM
Network
|
portainer
|
portainer
|
Portainer before 1.22.1 has XSS (issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-16878
|
2024-11-21 13:31 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224249
|
8.8 |
HIGH
Network
|
portainer
|
portainer
|
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
|
NVD-CWE-noinfo
|
CVE-2019-16877
|
2024-11-21 13:31 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224250
|
7.5 |
HIGH
Network
|
portainer
|
portainer
|
Portainer before 1.22.1 allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-16876
|
2024-11-21 13:31 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|