Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2022
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
CVSS Score
5.8
EPSS Score
0.002
Published
2022-06-22
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVSS Score
6.5
EPSS Score
0.17
Published
2022-06-22
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
CVSS Score
6.1
EPSS Score
0.002
Published
2022-06-22
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.
CVSS Score
5.3
EPSS Score
0.001
Published
2022-06-22
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-06-22
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
CVSS Score
5.5
EPSS Score
0.003
Published
2022-06-22
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
CVSS Score
3.5
EPSS Score
0.002
Published
2022-06-22
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-06-22
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
CVSS Score
3.5
EPSS Score
0.002
Published
2022-06-22
A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-06-22


Contact Us

Shodan ® - All rights reserved