3 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

28 Dec 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Ovation S.R.L. Dynamic Content for Elementor. Este problema afecta a Dynamic Content for Elementor: desde n/a antes de 2.12.5. • https://patchstack.com/database/vulnerability/dynamic-content-for-elementor/wordpress-dynamic-content-for-elementor-plugin-2-12-5-cross-site-request-forgery-csrf-leading-to-arbitrary-wordpress-options-change-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

19 Mar 2021 — Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. Ovation Dynamic Content versión 1.10.1 para Elementor, permite un ataque de tipo XSS por medio del parámetro post_title • https://gist.github.com/IthacaLabs/e69e90e1d0d9cb37bb3746b6a4274d29 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 1

26 Aug 2018 — Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a compression technique to prevent the identification of certain libraries in the software by obfuscation. The software relies on a TLS callback and an additional executable file to enable these librari... • https://github.com/GitHubAssessments/CVE_Assessment_02_2018/blob/master/FindMe_Report.pdf • CWE-20: Improper Input Validation •