4 results (0.008 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script. Vulnerabilidad de tipo cross-site scripting almacenado en Exment ((PHP8) exceedone/exment v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a un atacante remoto autenticado inyectar un script arbitrario. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script. Una vulnerabilidad de tipo cross-site scripting reflejado en Exment ((PHP8) exceedone/exment v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a un atacante remoto autenticado inyectar un script arbitrario. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands. Una vulnerabilidad de inyección SQL en Exment ((PHP8) exceedone/exment versiones v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment versiones v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a atacantes remotos autenticados ejecutar comandos SQL arbitrarios. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen. z-song laravel-admin versión 1.7.3, presenta una vulnerabilidad de tipo XSS por medio de Slug o Name en la pantalla Roles, debido a un manejo inapropiado en la pantalla "Operation log". • https://github.com/z-song/laravel-admin/issues/3847 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •