OTRS 6.0.1 – Remote Command Execution (2)
>> CATEGORY: Security
OTRS 6.0.1 – Remote Command Execution (2)
CMS Made Simple 2.2.15 – ‘title’ Cross-Site Scripting (XSS)
RemoteClinic 2 – ‘Multiple’ Cross-Site Scripting (XSS)
Fast PHP Chat 1.3 – ‘my_item_search’ SQL Injection
Multilaser Router RE018 AC1200 – Cross-Site Request Forgery (Enable Remote Access)
WordPress Plugin RSS for Yandex Turbo 1.29 – Stored Cross-Site Scripting (XSS)
BlackCat CMS 1.3.6 – ‘Multiple’ Stored Cross-Site Scripting (XSS)
Discourse 2.7.0 – Rate Limit Bypass leads to 2FA Bypass
Tenda D151 & D301 – Configuration Download (Unauthenticated)
GetSimple CMS My SMTP Contact Plugin 1.1.1 – CSRF to RCE