ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

6 results for “CVE-2023-4890”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2023-48906
Published
2024-04-01
CVSS:
4.3
ShadowTrackr CVSS:
0.6
Summary:
Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.
CVE:
CVE-2023-48903
Published
2024-03-21
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
CVE:
CVE-2023-48901
Published
2024-03-21
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
CVE:
CVE-2023-48902
Published
2024-03-21
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
CVE:
CVE-2023-48909
Published
2024-01-12
CVSS:
8.8
ShadowTrackr CVSS:
6.6
Summary:
An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.
CVE:
CVE-2023-4890
Published
2023-09-12
CVSS:
6.4
ShadowTrackr CVSS:
1.3
Summary:
The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.