CVE-2023-3144 – SourceCodester Online Discussion Forum Site manage_post.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3144
A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Peanut886/Vulnerability/blob/main/webray.com.cn/Online%20Discussion%20Forum%20Site%20-%20multiple%20vulnerabilities.md#10xss-vulnerability-in-adminpostsmanage_postphptitle https://vuldb.com/?ctiid.231013 https://vuldb.com/?id.231013 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-3143 – SourceCodester Online Discussion Forum Site manage_post.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3143
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Peanut886/Vulnerability/blob/main/webray.com.cn/Online%20Discussion%20Forum%20Site%20-%20multiple%20vulnerabilities.md#11xss-vulnerability-in-adminpostsmanage_postphpcontent https://vuldb.com/?ctiid.231012 https://vuldb.com/?id.231012 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-31296
https://notcve.org/view.php?id=CVE-2022-31296
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. Se ha detectado que Online Discussion Forum Site 1 contiene una vulnerabilidad de inyección SQL ciega por medio del componente /odfs/posts/view_post.php • https://github.com/bigzooooz/CVE-2022-31296 https://www.sourcecodester.com/php/15337/online-discussion-forum-site-phpoop-free-source-code.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-31295
https://notcve.org/view.php?id=CVE-2022-31295
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts. Un problema en la función delete_post() de Online Discussion Forum Site 1 permite a atacantes no autenticados eliminar mensajes de forma arbitraria • https://github.com/bigzooooz/CVE-2022-31295 https://www.sourcecodester.com/php/15337/online-discussion-forum-site-phpoop-free-source-code.html • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2022-31294
https://notcve.org/view.php?id=CVE-2022-31294
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts. Un problema en la función save_users() de Online Discussion Forum Site 1 permite a atacantes no autenticados crear o actualizar arbitrariamente cuentas de usuario • https://github.com/bigzooooz/CVE-2022-31294 https://www.sourcecodester.com/php/15337/online-discussion-forum-site-phpoop-free-source-code.html • CWE-352: Cross-Site Request Forgery (CSRF) •