Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ [PRODSECBUG-2448/2344] Cross side scripting via admin panel dashboard - CVE-2019-8120

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š [PRODSECBUG-2448/2344] Cross side scripting via admin panel dashboard - CVE-2019-8120


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: portal.patchman.co

An authenticated user could abuse the blockDirective() function and inject malicious JavaScript in the cache of the Admin and inject arbitrary JavaScript code by manipulating a section of a POST request that is related to customer's email address.

Part of update Magento 2.3.3 and 2.2.10 Security Update

This vulnerability affects the following application versions:

  • Magento 2.0.0
  • Magento 2.0.1
  • Magento 2.0.2
  • Magento 2.0.3
  • Magento 2.0.4
  • Magento 2.0.5
  • Magento 2.0.6
  • Magento 2.0.7
  • Magento 2.0.8
  • Magento 2.0.9
  • Magento 2.0.10
  • Magento 2.0.11
  • Magento 2.0.12
  • Magento 2.0.13
  • Magento 2.0.14
  • Magento 2.0.15
  • Magento 2.0.16
  • Magento 2.0.17
  • Magento 2.0.18
  • Magento 2.1.0
  • Magento 2.1.1
  • Magento 2.1.2
  • Magento 2.1.3
  • Magento 2.1.4
  • Magento 2.1.5
  • Magento 2.1.6
  • Magento 2.1.7
  • Magento 2.1.8
  • Magento 2.1.9
  • Magento 2.1.10
  • Magento 2.1.11
  • Magento 2.1.12
  • Magento 2.1.13
  • Magento 2.1.14
  • Magento 2.1.15
  • Magento 2.1.16
  • Magento 2.1.17
  • Magento 2.1.18
  • Magento 2.2.0
  • Magento 2.2.1
  • Magento 2.2.2
  • Magento 2.2.3
  • Magento 2.2.4
  • Magento 2.2.5
  • Magento 2.2.6
  • Magento 2.2.7
  • Magento 2.2.8
  • Magento 2.2.9
  • Magento 2.3.0
  • Magento 2.3.1
  • Magento 2.3.2
  • Magento 2.3.2-p1
  • Magento 2.3.2-p2
...



๐Ÿ“Œ [PRODSECBUG-2184] Stored cross-site scripting in the admin panel via the Terms & Conditions with Checkbox Text field in the admin panel


๐Ÿ“ˆ 63.98 Punkte

๐Ÿ“Œ [PRODSECBUG-2178] Stored cross-site scripting in the admin panel via the Admin Shopping Cart Rules page


๐Ÿ“ˆ 54.78 Punkte

๐Ÿ“Œ [PRODSECBUG-2229] Stored cross-site scripting in the admin panel via the Attribute Label for Media Attributes section


๐Ÿ“ˆ 47.96 Punkte

๐Ÿ“Œ [PRODSECBUG-2285] Remote code execution via server side request forgery issued to Redis


๐Ÿ“ˆ 34.51 Punkte

๐Ÿ“Œ PHP Scripts Mall Mall Advance Peer to Peer MLM Script 1.7.0 Admin Panel admin/dashboard.php information disclosure


๐Ÿ“ˆ 34.21 Punkte

๐Ÿ“Œ [PRODSECBUG-1860] Admin Account XSS Attack Cessation via Filename


๐Ÿ“ˆ 32.62 Punkte

๐Ÿ“Œ [PRODSECBUG-2038] Stored cross-site scripting vulnerability in the Admin through the Checkbox Custom Option Value field


๐Ÿ“ˆ 31.75 Punkte

๐Ÿ“Œ [PRODSECBUG-2136] Stored Cross-Site Scripting (XSS) in Admin


๐Ÿ“ˆ 31.75 Punkte

๐Ÿ“Œ [PRODSECBUG-2028] Stored cross-site scripting vulnerability in the Admin **Stores** > **Attributes** > **Product **configuration area


๐Ÿ“ˆ 31.75 Punkte

๐Ÿ“Œ [PRODSECBUG-204] Stored cross-site scripting vulnerability in Admin product names


๐Ÿ“ˆ 31.75 Punkte

๐Ÿ“Œ [PRODSECBUG-2126] Reflected cross-site scripting through manipulation of the Admin notification feed URL


๐Ÿ“ˆ 31.75 Punkte

๐Ÿ“Œ GD Rating System Plugin 2.3 on WordPress wp-admin/admin.php panel cross site scripting


๐Ÿ“ˆ 28.98 Punkte

๐Ÿ“Œ GD Rating System Plugin 2.3 on WordPress wp-admin/admin.php panel cross site scripting


๐Ÿ“ˆ 28.98 Punkte

๐Ÿ“Œ GD Rating System Plugin 2.3 on WordPress wp-admin/admin.php panel cross site scripting


๐Ÿ“ˆ 28.98 Punkte

๐Ÿ“Œ GD Rating System Plugin 2.3 on WordPress wp-admin/admin.php panel cross site scripting


๐Ÿ“ˆ 28.98 Punkte

๐Ÿ“Œ GD Rating System Plugin 2.3 auf WordPress wp-admin/admin.php panel Cross Site Scripting


๐Ÿ“ˆ 28.98 Punkte

๐Ÿ“Œ Combodo iTop up to 2.2.0 Dashboard Title dashboard.class.inc.php cross site scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Graylog up to 2.4.3 Dashboard Dashboard.jsx cross site scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Dashboard View Plugin up to 2.15 on Jenkins Image Dashboard Portlet cross site scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ OpenStack Dashboard bis 8.0.1/9.0.0/9.0.1 Dashboard Form Stack-Based Cross Site Scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ OpenStack Dashboard bis 8.0.1/9.0.0/9.0.1 Dashboard Form Stack-Based Cross Site Scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Combodo iTop bis 2.2.0 Dashboard Title dashboard.class.inc.php Cross Site Scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Graylog bis 2.4.3 Dashboard Dashboard.jsx Cross Site Scripting


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ [PRODSECBUG-2182] Reflected cross-site scriptingin in the product widget chooser section of the Admin


๐Ÿ“ˆ 28.53 Punkte

๐Ÿ“Œ OTCMS 3.85 Admin Panel admin/member_deal.php cross site request forgery


๐Ÿ“ˆ 25.76 Punkte

๐Ÿ“Œ [PRODSECBUG-2289] Arbitrary code execution in the advanced admin logging configuration


๐Ÿ“ˆ 25.61 Punkte

๐Ÿ“Œ [ PRODSECBUG-2123 ] PHP Object Injection (POI) and Remote Code Execution (RCE) in the Admin


๐Ÿ“ˆ 25.61 Punkte

๐Ÿ“Œ Kirby CMS/Panel Admin Panel getkirby/cms origin validation


๐Ÿ“ˆ 25.21 Punkte

๐Ÿ“Œ [PRODSECBUG-2236] SQL Injection and cross-site scripting vulnerability in Catalog section (XSS)


๐Ÿ“ˆ 24.93 Punkte

๐Ÿ“Œ Magento up to 1.9.4.1/2.1.17/2.2.8/2.3.1 Admin Panel Server-Side Request Forgery


๐Ÿ“ˆ 24.72 Punkte

๐Ÿ“Œ Techno Portfolio Management Panel panel/search.php s cross site scripting


๐Ÿ“ˆ 24.54 Punkte

๐Ÿ“Œ Flash Operator Panel 2.31.03 User Control Panel CSV File Persistent Cross Site Scripting


๐Ÿ“ˆ 24.54 Punkte

๐Ÿ“Œ Flash Operator Panel 2.31.03 User Control Panel CSV File Persistent Cross Site Scripting


๐Ÿ“ˆ 24.54 Punkte











matomo