| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| CWE-200: Exposure of Sensitive
Information to an Unauthorized Actor |
| CWE-284: Improper Access Control |
| CWE-306: Missing Authentication for Critical Function |
| WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. |
| HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions. |
| HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. |
| HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. |
| HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. |
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. |
| Subscriber SQL Injection in Do Lasso <= 358 versions. |
| Subscriber Path Traversal in Do Lasso <= 358 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. |
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. |