A vulnerability was found in RSVPMaker Excel Plugin up to 1.1 on WordPress (WordPress Plugin) and classified as problematic. Affected by this issue is an unknown function of the file ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php. Applying a patch is able to eliminate this problem. The bugfix is ready for download at plugins.trac.wordpress.org.
RSVPMaker Excel Plugin up to 1.1 on WordPress download.php $_SERVER[“PHP_SELF”] cross site scripting
- Virtual Patching
- September 10, 2021
- 5:04 pm
CVE-2024-45663 : IBM DB2/DB2 CONNECT SERVER 11.1/11.5 QUERY DENIAL OF SERVICE
Description IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial
CVE-2024-52739 : D-LINK DI-8400 16.07.26A1 MSP_INFO_HTM CMD PRIVILEGE ESCALATION
Description D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the
CVE-2024-52769 : DEDEBIZ 6.3.0 FILE /ADMIN/FRIENDLINK_EDIT UNRESTRICTED UPLOAD
Description An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via