A critical vulnerability in Aviatrix Controller is actively exploited to deploy backdoors and cryptocurrency miners in the wild. A security researcher Jakub Korepta discovered a critical vulnerability, tracked as CVE-2024-50603 (CVSS score: 10.0), in the Aviatrix Controller. The flaw impacts Aviatrix Controller pre-7.1.4191 and 7.2.x pre-7.2.4996, it allows unauthenticated attackers to execute arbitrary code via improper command […]
A vulnerability, which was classified as critical, was found in Selesta Visual Access Manager up to 4.42.1. This affects an unknown part of the file /vam/vam_visits.php of the component POST Parameter Handler. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-42244. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Selesta Visual Access Manager up to 4.42.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /vam/vam_ep.php. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-42246. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Selesta Visual Access Manager up to 4.42.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file monitor/s_monitor_map.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2023-42247. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Selesta Visual Access Manager up to 4.42.1. This vulnerability affects unknown code of the file monitor/s_scheduledfile.php. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2023-42245. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.