Recent Advisories

Severity ID Title Vendor Product Date Type
NONE PACKETSTORM:218859

📄 Pachno 1.0.6 Privilege Escalation_PACKETSTORM:218859

The authorization check in the runSwitchUser action in Pachno version 1.0.6 evaluates the expression !canSaveConfiguration && !hasCookie'originalus...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218861

📄 Pachno 1.0.6 FileCache Deserialization Remote Code Execution_PACKETSTORM:218861

Pachno version 1.0.6 uses the unserialize function on the contents of cache files stored under PACHNOPATH/cache/ during the framework bootstrap seq...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218854

📄 Pachno 1.0.6 Cross Site Scripting_PACKETSTORM:218854

Pachno version 1.0.6 suffers from persistent cross site scripting vulnerabilities...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218855

📄 Pachno 1.0.6 Open Redirection_PACKETSTORM:218855

Pachno version 1.0.6 suffers from an open redirection vulnerability. Input passed via the returnto GET/POST parameter to the login endpoint is not ...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218858

📄 Pachno 1.0.6 Wiki TextParser XML Injection_PACKETSTORM:218858

Pachno version 1.0.6 suffers from an XML eXternal Entity XXE vulnerability in the wiki textparser...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218856

📄 Pachno 1.0.6 Shell Upload_PACKETSTORM:218856

Pachno version 1.0.6 suffers from a remote shell upload vulnerability. The multipart file parameter to the /uploadfile endpoint allows authenticate...

N/A N/A PACKETSTORM
CRITICAL 9.3 PACKETSTORM:218820

📄 InvoicePlane 1.6.3 Path Traversal_PACKETSTORM:218820

InvoicePlane versions 1.6.3 and below suffer from a path traversal vulnerability in the getfile method of the Guest module...

N/A N/A PACKETSTORM
HIGH 8.3 PACKETSTORM:218731

📄 Redaxo 5.20.1 Path Traversal_PACKETSTORM:218731

Redaxo versions 5.20.1 and below suffer from a path traversal vulnerability...

N/A N/A PACKETSTORM
HIGH 8.7 PACKETSTORM:218745

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218745

OpenSTAManager versions 2.9.8 and below suffer from a remote time-based SQL injection vulnerability in the Article Pricing module...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218749

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218749

OpenSTAManager versions 2.9.8 and below suffer from a remote SQL injection vulnerability in ajaxcomplete.php...

N/A N/A PACKETSTORM