Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2023
A vulnerability classified as problematic has been found in zerochplus. This affects the function PrintResList of the file test/mordor/thread.res.pl. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named 9ddf9ecca8565341d8d26a3b2f64540bde4fa273. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218007.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-01-11
A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to fix this issue. VDB-218006 is the identifier assigned to this vulnerability.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-01-11
A vulnerability was found in Prestaul skeemas and classified as problematic. This issue affects some unknown processing of the file validators/base.js. The manipulation of the argument uri leads to inefficient regular expression complexity. The patch is named 65e94eda62dc8dc148ab3e59aa2ccc086ac448fd. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218003.
CVSS Score
3.5
EPSS Score
0.005
Published
2023-01-11
A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified as problematic. Affected is an unknown function of the file papaparse.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 5.2.0 is able to address this issue. The name of the patch is 235a12758cd77266d2e98fd715f53536b34ad621. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218004.
CVSS Score
3.5
EPSS Score
0.003
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-01-11
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-01-11


Contact Us

Shodan ® - All rights reserved