CVE-2023-24249
https://notcve.org/view.php?id=CVE-2023-24249
An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file. • https://github.com/IDUZZEL/CVE-2023-24249-Exploit https://flyd.uk/post/cve-2023-24249 https://github.com/z-song/laravel-admin https://laravel-admin.org • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-38089
https://notcve.org/view.php?id=CVE-2022-38089
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script. Vulnerabilidad de tipo cross-site scripting almacenado en Exment ((PHP8) exceedone/exment v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a un atacante remoto autenticado inyectar un script arbitrario. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-38080
https://notcve.org/view.php?id=CVE-2022-38080
Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script. Una vulnerabilidad de tipo cross-site scripting reflejado en Exment ((PHP8) exceedone/exment v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a un atacante remoto autenticado inyectar un script arbitrario. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-37333
https://notcve.org/view.php?id=CVE-2022-37333
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands. Una vulnerabilidad de inyección SQL en Exment ((PHP8) exceedone/exment versiones v5.0.2 y anteriores y exceedone/laravel-admin v3.0.0 y anteriores, (PHP7) exceedone/exment versiones v4.4.2 y anteriores y exceedone/laravel-admin v2.2.2 y anteriores) permite a atacantes remotos autenticados ejecutar comandos SQL arbitrarios. • https://exment.net/docs/#/release_note?id=v503-20220817 https://exment.net/docs/#/weakness/20220817 https://jvn.jp/en/jp/JVN46239102/index.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •