Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Nextcloud: Stored XSS in collabora via user name

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Nextcloud: Stored XSS in collabora via user name


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Affected: collabora and nextcloud Ubuntu 18.04.5 LTS Nextcloud 19.0.1 snap version collabora (CODE) The name of the user is displayed when him joins to edit the document allowing the attacker trigger xss. Impact Set the name of the attacker account to Create a new document โ†’ share the document with admin or another victim โ†’ the document will appear automatically in the files of the victim as shared The attacker opens the document and waits until the victim also opens the document when opening it the payload is executed ... ...



๐Ÿ“Œ Nextcloud: Stored XSS in collabora via user name


๐Ÿ“ˆ 66.06 Punkte

๐Ÿ“Œ Collabora Productivity announces a new major release - Collabora Office 6.0


๐Ÿ“ˆ 34.55 Punkte

๐Ÿ“Œ [webapps] Task Management System 1.0 - 'First Name and Last Name' Stored XSS


๐Ÿ“ˆ 32.15 Punkte

๐Ÿ“Œ #0daytoday #Task Management System 1.0 - (First Name and Last Name) Stored XSS Vulnerability [#0day #Exploit]


๐Ÿ“ˆ 32.15 Punkte

๐Ÿ“Œ [webapps] Customer Support System 1.0 - "First Name" & "Last Name" Stored XSS


๐Ÿ“ˆ 32.15 Punkte

๐Ÿ“Œ #0daytoday #Customer Support System 1.0 - First Name & Last Name Stored XSS Vulnerabili [#0day #Exploit]


๐Ÿ“ˆ 32.15 Punkte

๐Ÿ“Œ Nextcloud: XSS in Desktop Client via user status and information


๐Ÿ“ˆ 32.03 Punkte

๐Ÿ“Œ WordPress: Stored XSS on byddypress Plug-in via groups name


๐Ÿ“ˆ 31.21 Punkte

๐Ÿ“Œ lemlist: stored xss via Campaign Name.


๐Ÿ“ˆ 31.21 Punkte

๐Ÿ“Œ Shopify: Blind Stored XSS Via Staff Name


๐Ÿ“ˆ 31.21 Punkte

๐Ÿ“Œ Logitech: Stored XSS on oslo.io in notifications via project name change


๐Ÿ“ˆ 31.21 Punkte

๐Ÿ“Œ Nextcloud: Reflected XSS vulnerability with full CSP bypass in Nextcloud installations using recommended bundle


๐Ÿ“ˆ 30.99 Punkte

๐Ÿ“Œ FetLife: Stored XSS via Angular Expression injection via Subject while starting conversation with other users.


๐Ÿ“ˆ 30.27 Punkte

๐Ÿ“Œ XSS-LOADER - XSS Payload Generator / XSS Scanner / XSS Dork Finder


๐Ÿ“ˆ 29.79 Punkte

๐Ÿ“Œ CVE-2022-3518 | SourceCodester Sanitization Management System 1.0 User Creation First Name/Middle Name/Last Name cross site scripting


๐Ÿ“ˆ 29.65 Punkte

๐Ÿ“Œ CVE-2024-0782 | CodeAstro Online Railway Reservation System 1.0 pass-profile.php First Name/Last Name/User Name cross site scripting


๐Ÿ“ˆ 29.65 Punkte

๐Ÿ“Œ Artikel: Collabora โ€“ so klappt die Zusammenarbeit im Online-Office von Nextcloud


๐Ÿ“ˆ 29.05 Punkte

๐Ÿ“Œ CVE-2023-25150 | Nextcloud Office Richdocuments Collabora access control (GHSA-64xc-r58v-53gj)


๐Ÿ“ˆ 29.05 Punkte

๐Ÿ“Œ Nextcloud 11, Collabora Online 2.0 Allow Collaborative Editing from Shared Links


๐Ÿ“ˆ 29.05 Punkte

๐Ÿ“Œ Nextcloud 11, Collabora Online 2.0 Allow Collaborative Editing from Shared Links


๐Ÿ“ˆ 29.05 Punkte

๐Ÿ“Œ CVE-2022-39346 | Nextcloud Server prior 22.2.10/23.0.7/24.0.3 User Display Name resource consumption (GHSA-6w9f-jgjx-4vj6)


๐Ÿ“ˆ 25.52 Punkte

๐Ÿ“Œ PHP Scripts Mall Advance B2B Script 2.1.4 FIRST NAME/LAST NAME Stored cross site scripting


๐Ÿ“ˆ 24.7 Punkte

๐Ÿ“Œ Sichere Dokumentenfreigabe in ownCloud via Collabora


๐Ÿ“ˆ 24.28 Punkte

๐Ÿ“Œ [APPSEC-1545] Stored XSS through customer group name in admin panel


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ Mail.ru: Blind XSS Stored On Admin Panel Through Name Parameter In [ https://technoatom.mail.ru/]


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ Localize: Stored XSS in Name of Team Member Invitation


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ Shopify: Stored XSS in my staff name fired in another your internal panel


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ [APPSEC-1885] Stored XSS in Product Name field


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ Mapbox: Stored XSS | api.mapbox.com | IE 11 | Styles name


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ [webapps] Courier Management System 1.0 - 'First Name' Stored XSS


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ #0daytoday #Courier Management System 1.0 - (First Name) Stored XSS Vulnerability [#0day #Exploit]


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ [webapps] Content Management System 1.0 - 'First Name' Stored XSS


๐Ÿ“ˆ 24.2 Punkte

๐Ÿ“Œ #0daytoday #Content Management System 1.0 - (First Name) Stored XSS Vulnerability [#0day #Exploit]


๐Ÿ“ˆ 24.2 Punkte











matomo