Latest vulnerabilities of Sunday, September 17, 2023

Latest vulnerabilities of Sunday, September 17, 2023
https://www.securitricks.com/content/images/size/w600/format/webp/2023/12/VULNERABILITIES-REPORTS-LOGO.png
{{titre}}

Last update performed on 09/17/2023 at 11:58:27 PM

(0) CRITICAL VULNERABILITIES [9.0, 10.0]

(1) HIGH VULNERABILITIES [7.0, 8.9]

Source : vuldb.com

Vulnerability ID : CVE-2023-5020

First published on : 17-09-2023 05:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of the file /index.php/sysmanage/Login/login_auth/ of the component Administrator Login Page. The manipulation of the argument account leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239861 was assigned to this vulnerability.

CVE ID : CVE-2023-5020
Source : cna@vuldb.com
CVSS Score : 7.3

References :
https://github.com/chosir/exp/tree/main | source : cna@vuldb.com
https://vuldb.com/?ctiid.239861 | source : cna@vuldb.com
https://vuldb.com/?id.239861 | source : cna@vuldb.com

Vulnerability : CWE-89


(8) MEDIUM VULNERABILITIES [4.0, 6.9]

Source : vuldb.com

Vulnerability ID : CVE-2023-5014

First published on : 17-09-2023 01:15:34
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239855.

CVE ID : CVE-2023-5014
Source : cna@vuldb.com
CVSS Score : 6.3

References :
https://github.com/TheCyberDiver/Public-Disclosures-CVE-/blob/main/Food-Ordering-Website%20SQLi.md | source : cna@vuldb.com
https://vuldb.com/?ctiid.239855 | source : cna@vuldb.com
https://vuldb.com/?id.239855 | source : cna@vuldb.com

Vulnerability : CWE-89


Vulnerability ID : CVE-2023-5016

First published on : 17-09-2023 02:15:08
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.getConnection of the file src/main/java/org/spiderflow/controller/DataSourceController.java of the component API. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239857 was assigned to this vulnerability.

CVE ID : CVE-2023-5016
Source : cna@vuldb.com
CVSS Score : 6.3

References :
https://github.com/bayuncao/vul-cve | source : cna@vuldb.com
https://github.com/bayuncao/vul-cve/blob/main/spider-flow%20fastjson%20jdbc%20deserialization | source : cna@vuldb.com
https://vuldb.com/?ctiid.239857 | source : cna@vuldb.com
https://vuldb.com/?id.239857 | source : cna@vuldb.com

Vulnerability : CWE-502


Vulnerability ID : CVE-2023-5018

First published on : 17-09-2023 04:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_category of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-239859.

CVE ID : CVE-2023-5018
Source : cna@vuldb.com
CVSS Score : 6.3

References :
https://vuldb.com/?ctiid.239859 | source : cna@vuldb.com
https://vuldb.com/?id.239859 | source : cna@vuldb.com

Vulnerability : CWE-89


Vulnerability ID : CVE-2023-5019

First published on : 17-09-2023 04:15:11
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability classified as critical was found in Tongda OA. This vulnerability affects unknown code of the file general/hr/manage/staff_reinstatement/delete.php. The manipulation of the argument REINSTATEMENT_ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-239860.

CVE ID : CVE-2023-5019
Source : cna@vuldb.com
CVSS Score : 6.3

References :
https://github.com/ggg48966/cve/blob/main/sql.md | source : cna@vuldb.com
https://vuldb.com/?ctiid.239860 | source : cna@vuldb.com
https://vuldb.com/?id.239860 | source : cna@vuldb.com

Vulnerability : CWE-89


Vulnerability ID : CVE-2023-5027

First published on : 17-09-2023 17:15:44
Last modified on : 17-09-2023 17:15:44

Description :
A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability.

CVE ID : CVE-2023-5027
Source : cna@vuldb.com
CVSS Score : 6.3

References :
https://github.com/LianghaoW/CveHub/blob/main/Simple-Membership-System%20club_validator.php%20has%20Sqlinjection.pdf | source : cna@vuldb.com
https://vuldb.com/?ctiid.239869 | source : cna@vuldb.com
https://vuldb.com/?id.239869 | source : cna@vuldb.com

Vulnerability : CWE-89


Vulnerability ID : CVE-2023-5017

First published on : 17-09-2023 03:15:08
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in lmxcms up to 1.41. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin.php. The manipulation of the argument lid leads to sql injection. VDB-239858 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE ID : CVE-2023-5017
Source : cna@vuldb.com
CVSS Score : 5.5

References :
https://vuldb.com/?ctiid.239858 | source : cna@vuldb.com
https://vuldb.com/?id.239858 | source : cna@vuldb.com

Vulnerability : CWE-89


Vulnerability ID : CVE-2023-5022

First published on : 17-09-2023 06:15:07
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.

CVE ID : CVE-2023-5022
Source : cna@vuldb.com
CVSS Score : 5.5

References :
https://github.com/bayuncao/DEDEcms | source : cna@vuldb.com
https://vuldb.com/?ctiid.239863 | source : cna@vuldb.com
https://vuldb.com/?id.239863 | source : cna@vuldb.com

Vulnerability : CWE-36


Vulnerability ID : CVE-2023-5023

First published on : 17-09-2023 07:15:09
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_relatives/delete.php. The manipulation of the argument RELATIVES_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239864.

CVE ID : CVE-2023-5023
Source : cna@vuldb.com
CVSS Score : 5.5

References :
https://github.com/RCEraser/cve/blob/main/sql_inject_3.md | source : cna@vuldb.com
https://vuldb.com/?ctiid.239864 | source : cna@vuldb.com
https://vuldb.com/?id.239864 | source : cna@vuldb.com

Vulnerability : CWE-89


(6) LOW VULNERABILITIES [0.1, 3.9]

Source : vuldb.com

Vulnerability ID : CVE-2023-5015

First published on : 17-09-2023 02:15:07
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239856.

CVE ID : CVE-2023-5015
Source : cna@vuldb.com
CVSS Score : 3.5

References :
https://github.com/Num-Nine/CVE/issues/3 | source : cna@vuldb.com
https://vuldb.com/?ctiid.239856 | source : cna@vuldb.com
https://vuldb.com/?id.239856 | source : cna@vuldb.com

Vulnerability : CWE-79


Vulnerability ID : CVE-2023-5021

First published on : 17-09-2023 05:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability, which was classified as problematic, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file admin/?page=system_info/contact_information. The manipulation of the argument telephone/mobile/address leads to cross site scripting. It is possible to launch the attack remotely. VDB-239862 is the identifier assigned to this vulnerability.

CVE ID : CVE-2023-5021
Source : cna@vuldb.com
CVSS Score : 3.5

References :
https://vuldb.com/?ctiid.239862 | source : cna@vuldb.com
https://vuldb.com/?id.239862 | source : cna@vuldb.com

Vulnerability : CWE-79


Vulnerability ID : CVE-2023-5024

First published on : 17-09-2023 07:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the component Comment Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239865 was assigned to this vulnerability.

CVE ID : CVE-2023-5024
Source : cna@vuldb.com
CVSS Score : 3.5

References :
https://vuldb.com/?ctiid.239865 | source : cna@vuldb.com
https://vuldb.com/?id.239865 | source : cna@vuldb.com
https://www.planno.fr/ | source : cna@vuldb.com
https://youtu.be/evdhcUlD1EQ | source : cna@vuldb.com

Vulnerability : CWE-79


Vulnerability ID : CVE-2023-5025

First published on : 17-09-2023 07:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239866 is the identifier assigned to this vulnerability.

CVE ID : CVE-2023-5025
Source : cna@vuldb.com
CVSS Score : 3.5

References :
https://vuldb.com/?ctiid.239866 | source : cna@vuldb.com
https://vuldb.com/?id.239866 | source : cna@vuldb.com
https://www.youtube.com/watch?v=b5107YkpgaM | source : cna@vuldb.com

Vulnerability : CWE-79


Vulnerability ID : CVE-2023-5026

First published on : 17-09-2023 10:15:07
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV. The manipulation of the argument OA_SUB_WINDOW leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239868.

CVE ID : CVE-2023-5026
Source : cna@vuldb.com
CVSS Score : 3.5

References :
https://github.com/Mykonos-x/cve/tree/main/cve/tongda/v11/xss | source : cna@vuldb.com
https://vuldb.com/?ctiid.239868 | source : cna@vuldb.com
https://vuldb.com/?id.239868 | source : cna@vuldb.com

Vulnerability : CWE-79


Vulnerability ID : CVE-2023-5028

First published on : 17-09-2023 11:15:07
Last modified on : 17-09-2023 12:00:56

Description :
A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-239870 is the identifier assigned to this vulnerability.

CVE ID : CVE-2023-5028
Source : cna@vuldb.com
CVSS Score : 2.0

References :
https://github.com/pinglan123/-/wiki/%E4%B8%AD%E5%9B%BD%E8%81%94%E9%80%9A%E5%AE%B6%E7%94%A8%E7%BD%91%E5%85%B3 | source : cna@vuldb.com
https://vuldb.com/?ctiid.239870 | source : cna@vuldb.com
https://vuldb.com/?id.239870 | source : cna@vuldb.com

Vulnerability : CWE-534


(1) NO SCORE VULNERABILITIES [0.0, 0.0]

Source : hackerone.com

Vulnerability ID : CVE-2023-38040

First published on : 17-09-2023 05:15:10
Last modified on : 17-09-2023 12:00:56

Description :
A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

CVE ID : CVE-2023-38040
Source : support@hackerone.com
CVSS Score : /

References :
https://hackerone.com/reports/1694171 | source : support@hackerone.com


This website uses the NVD API, but is not approved or certified by it.

About the author
Julien B.

Securitricks

Up-to-Date Cybersecurity Insights & Malware Reports

Securitricks

Great! Youโ€™ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Securitricks.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.