CVE-2020-28459
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. Zafiyet ile ilgili Genel Bilgi,…
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. Zafiyet ile ilgili Genel Bilgi,…
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they…
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they…
This affects the package properties-reader before 2.2.0. Zafiyet ile ilgili Genel Bilgi, Etki ve Çözümleri için Devamını Oku Kaynak: National Vulnerability Database
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk’s internal network via directory traversal. Zafiyet ile…
All versions of package git-archive are vulnerable to Command Injection via the exports function. Zafiyet ile ilgili Genel Bilgi, Etki ve Çözümleri için Devamını Oku…
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action,…
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading…
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a…
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to…