CVE-2023-49833 – WordPress Spectra Plugin <= 2.7.9 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-49833
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9. Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en Brainstorm Force Spectra – WordPress Gutenberg Blocks permite almacenar XSS. Este problema afecta a Spectra – WordPress Gutenberg Blocks: desde n/a hasta 2.7.9. The Spectra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/ultimate-addons-for-gutenberg/wordpress-spectra-plugin-2-7-9-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-36656 – Spectra < 1.15.0 - Contributor+ Stored Cross-Side Scripting
https://notcve.org/view.php?id=CVE-2020-36656
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.14.11 due to insufficient sanitizing of input in Gutenberg blocks. This makes it possible for contributors, or higher privileged users, to inject arbitrary web scripts that execute in a victim's browser. • https://wpscan.com/vulnerability/10f7e892-7a91-4292-b03e-6ad75756488b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-25966
https://notcve.org/view.php?id=CVE-2020-25966
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system. ** EN DISPUTA ** Sectona Spectra versiones anteriores a 3.4.0, presenta un endpoint de la API SOAP vulnerable que filtra información confidencial sobre los activos configurados sin la autenticación apropiada. Esto podría ser usado por partes no autorizadas para obtener credenciales de inicio de sesión configuradas de los activos por medio de un valor de pAccountID modificado. NOTA: El proveedor ha indicado que esto no es una vulnerabilidad y afirma "Esta vulnerabilidad se produjo debido a una configuración errónea del sistema" • https://gitlab.com/Gazzaz/Spectra_API_Issue https://sectona.com/products/spectra-privileged-access-management • CWE-306: Missing Authentication for Critical Function •
CVE-2020-36702 – Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization
https://notcve.org/view.php?id=CVE-2020-36702
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings. • https://blog.nintechnet.com/wordpress-ultimate-addons-for-gutenberg-plugin-fixed-vulnerability https://www.wordfence.com/threat-intel/vulnerabilities/id/4419a302-4305-44f8-a256-dd276b5cd751?source=cve • CWE-862: Missing Authorization •
CVE-2000-0862
https://notcve.org/view.php?id=CVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information. • http://archives.neohapsis.com/archives/vendor/2000-q3/0059.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5466 •