A vulnerability was found in Best Practical Request Tracker up to 4.2.16/4.4.4/5.0.1 (Ticket Tracking Software). It has been declared as problematic. Affected by this vulnerability is an unknown code block in the library lib/RT/REST2/Middleware/Auth.pm. Upgrading to version 4.2.17, 4.4.5 or 5.0.2 eliminates this vulnerability. The upgrade is hosted for download at docs.bestpractical.com. Applying the patch 70749bb66cb13dd70bd53340c371038a5f3ca57c is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.
Best Practical Request Tracker up to 4.2.16/4.4.4/5.0.1 Auth.pm timing discrepancy
- Virtual Patching
- October 18, 2021
- 12:04 pm
CVE-2023-29632 : JMSPAGEBUILDER 3.X ON PRESTASHOP AJAX_JMSPAGEBUILDER.PHP SQL INJECTION
Description PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php. References https://friends-of-presta.github.io/security-advisories/modules/2023/03/13/jmspagebuilder.html For More Information MITRE
CVE-2023-3065 : MOBATIME AMXGT100 UP TO 1.3.20 IMPROPER AUTHENTICATION
Description Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
CVE-2023-2781 : USER EMAIL VERIFICATION FOR WOOCOMMERCE PLUGIN UP TO 3.5.0 ON WORDPRESS IMPROPER AUTHENTICATION
Description The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up