Search Results (44267 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-16968 1 Fusionpbx 1 Fusionpbx 2024-11-21 6.1 Medium
An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.
CVE-2019-16967 2 Freepbx, Sangoma 2 Manager, Freepbx 2024-11-21 6.1 Medium
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.
CVE-2019-16966 2 Freepbx, Sangoma 2 Contactmanager, Freepbx 2024-11-21 6.1 Medium
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. It can be requested via a GET request to /admin/ajax.php?module=contactmanager.
CVE-2019-16962 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 5.4 Medium
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
CVE-2019-16961 1 Solarwinds 1 Web Help Desk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
CVE-2019-16960 1 Solarwinds 1 Web Help Desk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
CVE-2019-16958 1 Solarwinds 1 Help Desk 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
CVE-2019-16957 1 Solarwinds 1 Webhelpdesk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
CVE-2019-16956 1 Solarwinds 1 Web Help Desk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
CVE-2019-16955 1 Solarwinds 1 Webhelpdesk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
CVE-2019-16954 1 Solarwinds 1 Web Help Desk 2024-11-21 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
CVE-2019-16950 1 Enghouse 1 Web Chat 2024-11-21 6.1 Medium
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.
CVE-2019-16935 4 Canonical, Debian, Python and 1 more 6 Ubuntu Linux, Debian Linux, Python and 3 more 2024-11-21 6.1 Medium
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
CVE-2019-16931 1 Themeisle 1 Visualizer 2024-11-21 6.1 Medium
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
CVE-2019-16926 1 Flower Project 1 Flower 2024-11-21 6.1 Medium
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access
CVE-2019-16925 1 Flower Project 1 Flower 2024-11-21 6.1 Medium
Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access
CVE-2019-16923 1 Kkcms Project 1 Kkcms 2024-11-21 6.1 Medium
kkcms 1.3 has jx.php?url= XSS.
CVE-2019-16914 1 Netgate 1 Pfsense 2024-11-21 6.1 Medium
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
CVE-2019-16904 1 Teampass 1 Teampass 2024-11-21 5.4 Medium
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
CVE-2019-16890 1 Halo 1 Halo 2024-11-21 5.4 Medium
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.