Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2023
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can enumerate users logins. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVSS Score
5.3
EPSS Score
0.003
Published
2023-09-27
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user that have read access on users resource can steal accounts of other users. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVSS Score
8.1
EPSS Score
0.003
Published
2023-09-27
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A logged user from any profile can hijack the Kanban feature to alter any user field, and end-up with stealing its account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVSS Score
8.1
EPSS Score
0.002
Published
2023-09-27
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions.
CVSS Score
7.1
EPSS Score
0.002
Published
2023-09-27
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-09-27
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-09-27
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-09-27
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
CVSS Score
3.7
EPSS Score
0.001
Published
2023-09-27
Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-09-27
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-09-27


Contact Us

Shodan ® - All rights reserved