3 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

08 Sep 2023 — CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json. Se descubrió que CMysten Labs Sui blockchain v1.2.0 contiene un desbordamiento de pila a través del componente "/spec/openrpc.json". • https://github.com/MystenLabs/sui/commit/8b681515c0cf435df2a54198a28ab4ef574d202b • CWE-787: Out-of-bounds Write •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

11 Mar 2018 — The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. El plugin bbp-move-topics versiones anteriores a 1.1.6 para WordPress, presenta una inyección de código. The bbPress Move Topics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.4 via deserialization of untrusted input via the 'aforums_move_topics_page()' function where it passes the decoded 'allforums' value through the 'unserialize()' function. This allows authenticated attackers to in... • https://wordpress.org/plugins/bbp-move-topics/#developers • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-502: Deserialization of Untrusted Data •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

11 Mar 2018 — The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. El plugin bbp-move-topics versiones anteriores a 1.1.6 para WordPress, tiene una vulnerabilidad de tipo CSRF. The bbp-move-topics plugin before 1.1.5 for WordPress has CSRF. • https://wordpress.org/plugins/bbp-move-topics/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •