A vulnerability, which was classified as problematic, was found in OS4Ed openSIS 8.0. This affects an unknown code block of the file Ajax_url_encode.php of the component Parameter Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
OS4Ed openSIS 8.0 Parameter Ajax_url_encode.php link_url cross site scripting
- Virtual Patching
- October 12, 2021
- 9:05 am
CVE-2023-27982 : SCHNEIDER ELECTRIC IGSS DATA SERVER/IGSS DASHBOARD/CUSTOM REPORTS UP TO 16.0.0.23040 DASHBOARD FILE DATA AUTHENTICITY
Description A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard
CVE-2023-1501 : ROCKOA 2.3.2 ACLOUDCOSACTION.PHP.SQL RUNACTION FILEID UNRESTRICTED UPLOAD
Description A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the
CVE-2023-28116 : CONTIKI-NG UP TO 4.8/4.9 BLE L2CAP MODULE PACKETBUF_SIZE BUFFER OVERFLOW
Description Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an