Page 4 of 19 results (0.008 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. La falta de saneamiento de los resultados de búsqueda para un campo de autocompletado en NextCloud Talk en versiones anteriores a la 3.2.5 podría provocar un Cross-Site Scripting (XSS) persistente que requiera la interacción del usuario. La falta de saneamiento solo afectaba a los nombres de usuario, por lo que los resultados de búsqueda maliciosos solo pueden ser manipulados por los usuarios autenticados. • https://hackerone.com/reports/383117 https://nextcloud.com/security/advisory/?id=NC-SA-2018-009 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive information. El módulo Talk 5.x y versiones anteriores a 5.x-1.3 y 6.x y versiones anteriores a 6.x-1.5, para Drupal, no realiza comprobación de acceso para un nodo antes de mostrar comentarios, lo que permite a los atacantes remotos obtener información delicada. • http://drupal.org/node/309758 http://secunia.com/advisories/31908 http://www.securityfocus.com/bid/31236 http://www.vupen.com/english/advisories/2008/2615 https://exchange.xforce.ibmcloud.com/vulnerabilities/45223 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 3.5EPSS: 0%CPEs: 7EXPL: 0

Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Talk 5.x y versiones anteriores a 5.x-1.3 y 6.x versiones anteriores a 6.x-1.5, para Drupal, permite a los usuarios autenticados remotamente insertar arbitrariamente una secuencia de comandos web o HTML a través del nodo título. • http://drupal.org/node/309758 http://secunia.com/advisories/31908 http://www.securityfocus.com/bid/31236 http://www.vupen.com/english/advisories/2008/2615 https://exchange.xforce.ibmcloud.com/vulnerabilities/45222 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender. • http://marc.info/?l=bugtraq&m=113156797404902&w=2 http://marc.info/?l=bugtraq&m=113200923423283&w=2 http://www.securityfocus.com/bid/15369 https://exchange.xforce.ibmcloud.com/vulnerabilities/23041 • CWE-20: Improper Input Validation •