Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.
CVSS Score
6.4
EPSS Score
0.001
Published
2024-10-25
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-10-25
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.
CVSS Score
9.8
EPSS Score
0.026
Published
2024-10-25
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
CVSS Score
9.8
EPSS Score
0.021
Published
2024-10-25
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
CVSS Score
9.8
EPSS Score
0.014
Published
2024-10-25
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.
CVSS Score
9.8
EPSS Score
0.014
Published
2024-10-25
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-10-25
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-10-25
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-10-25
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.
CVSS Score
7.5
EPSS Score
0.087
Published
2024-10-25


Contact Us

Shodan ® - All rights reserved