CVE-2022-34619 : MEALIE 0.5.5 SHOPPING LISTS ITEM NAMES CROSS SITE SCRIPTING

Description

A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.

References

https://cwe.mitre.org/data/definitions/79.html

https://docs.mealie.io/changelog/v0.5.6/

https://gainsec.com/2022/08/02/cve-2022-34613-cve-2022-34618-cve-2022-34619-xss-file-upload-and-more/

https://hub.docker.com/r/hkotel/mealie

https://huntr.dev/bounties/aa610613-6ebb-4544-9aa6-046dc28fe4ff/

For More Information

MITRE

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-45359 : YITH WOOCOMMERCE GIFT CARDS PREMIUM PLUGIN UP TO 3.19.0 ON WORDPRESS UNRESTRICTED UPLOAD

CVE-2022-45359 : YITH WOOCOMMERCE GIFT CARDS PREMIUM PLUGIN UP TO 3.19.0 ON WORDPRESS UNRESTRICTED UPLOAD

Description Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin

CVE-2022-45479 : PC KEYBOARD SERVER MISSING AUTHENTICATION

CVE-2022-45479 : PC KEYBOARD SERVER MISSING AUTHENTICATION

Description PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous

CVE-2022-46414 : VERITAS NETBACKUP FLEX SCALE/ACCESS APPLIANCE MANAGEMENT PORTAL REMOTE CODE EXECUTION

CVE-2022-46414 : VERITAS NETBACKUP FLEX SCALE/ACCESS APPLIANCE MANAGEMENT PORTAL REMOTE CODE EXECUTION

Description An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command