|
209891
|
6.1 |
MEDIUM
Network
|
apache
|
sling_cms
|
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1949
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209892
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
|
CWE-79
Cross-site Scripting
|
CVE-2020-1943
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209893
|
7.8 |
HIGH
Local
|
systemd_project redhat debian
|
systemd enterprise_linux openshift_container_platform discovery migration_toolkit ceph_storage debian_linux
|
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse…
|
CWE-416
Use After Free
|
CVE-2020-1712
|
2024-11-21 14:11 |
2020-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209894
|
8.1 |
HIGH
Network
|
otrs
|
otrs
|
An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, passw…
|
CWE-331
Insufficient Entropy
|
CVE-2020-1773
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209895
|
7.5 |
HIGH
Network
|
otrs opensuse debian
|
otrs leap backports_sle debian_linux
|
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue…
|
NVD-CWE-noinfo
|
CVE-2020-1772
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209896
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs
|
Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter enc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1771
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209897
|
4.3 |
MEDIUM
Network
|
otrs opensuse debian
|
otrs leap backports_sle debian_linux
|
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior …
|
CWE-200
Information Exposure
|
CVE-2020-1770
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209898
|
4.3 |
MEDIUM
Network
|
otrs opensuse
|
otrs leap backports_sle
|
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0…
|
NVD-CWE-noinfo
|
CVE-2020-1769
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209899
|
7.8 |
HIGH
Local
|
huawei
|
p30_firmware
|
HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unau…
|
NVD-CWE-noinfo
|
CVE-2020-1800
|
2024-11-21 14:11 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209900
|
8.6 |
HIGH
Network
|
kiali redhat
|
kiali openshift_service_mesh
|
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT sign…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-1764
|
2024-11-21 14:11 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|