Shopmetrics Mystery Shopping Software SaaS platform versions before v21-11 suffer from broken access control and cross site scripting vulnerabilities.
>> ARCHIVE: 2022-02
Feberr version 12.7 suffers from a remote shell upload vulnerability.
Vivellio version 1.2.1 suffers from a user account enumeration vulnerability.
Servisnet Tessa – Add sysAdmin User (Unauthenticated) (Metasploit)
Servisnet Tessa – Privilege Escalation (Metasploit)
WordPress Plugin IP2Location Country Blocker 2.26.7 – Stored Cross Site Scripting (XSS) (Authenticated)
FLAME II MODEM USB – Unquoted Service Path
WBCE CMS 1.5.2 – Remote Code Execution (RCE) (Authenticated)
Servisnet Tessa – MQTT Credentials Dump (Unauthenticated) (Metasploit)
CONTPAQi AdminPAQ version 14.0.0 suffers from an unquoted service path vulnerability.