CSZ CMS 1.3.0 is affected by a cross-site scripting (XSS) feature that allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Gallery' section and choosing our Gallery. previously created, in the 'YouTube URL' field, this input is affected by an XSS. It should be noted that previously when creating a gallery the "Name" field was vulnerable to XSS, but this was resolved in the current version 1.3.0, the vulnerability found affects the "YouTube URL" field within the created gallery.
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
Allows Attacker to upload malicious files onto the server, such as Stored XSS
SQL injection attacks can allow unauthorized access to sensitive data, modification of data and crash the application or make it unavailable, leading to lost revenue and damage to a company's reputation.
Stack buffer overflow vulnerability in NVClient v5.0 allows attackers to cause a denial of service (crash) via a crafted payload in the Contact box.
This exploit allows remote code execution in Ivanti Avalanche version v6.4.0.0. By exploiting this vulnerability, an attacker can execute arbitrary code on the target system.
Allows Attacker to upload malicious files onto the server, such as Stored XSS
The Blood Donor Management System v1.0 is vulnerable to stored XSS. An attacker can inject malicious script in the 'State' input field, which will be executed when a user visits the welcome page.
Authenticated user privileges to tickets. User can send XSS to admin or other user and steal session.
The User Registration & Login and User Management System v3.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain unauthorized access to the admin portal and download all the data from the database.