|
256181
|
3.7 |
LOW
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-32939
|
2024-08-24 01:17 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256182
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged …
|
NVD-CWE-noinfo
|
CVE-2024-39836
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256183
|
4.9 |
MEDIUM
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsear…
|
NVD-CWE-noinfo
|
CVE-2024-39810
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256184
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.
|
CWE-89
SQL Injection
|
CVE-2024-42782
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256185
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email para…
|
CWE-89
SQL Injection
|
CVE-2024-42781
|
2024-08-24 01:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256186
|
6.3 |
MEDIUM
Network
|
youdiancms
|
youdiancms
|
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation o…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-7330
|
2024-08-24 01:12 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256187
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-42780
|
2024-08-24 01:10 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256188
|
8.8 |
HIGH
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-sid…
|
CWE-352
Origin Validation Error
|
CVE-2024-40886
|
2024-08-24 01:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256189
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-42779
|
2024-08-24 01:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256190
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a craf…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-42777
|
2024-08-24 01:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|