Aggregator
Weekly Update 442
9 months 1 week ago
We survived the cyclone! That was a seriously weird week with lots of build-up to an event that last occurred before I was born. It'd been 50 years since a cyclone came this far south, and the media was full of alarming predictions of destruction. In the end,
Troy Hunt
CVE-2025-2118 | Quantico Tecnologia PRMV 6.48 Login Endpoint /admin/login.php username sql injection
9 months 1 week ago
A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Login Endpoint. The manipulation of the argument username leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-2118. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2117 | Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System reportCenter.do electricDocList sql injection
9 months 1 week ago
A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is the function electricDocList of the file /newsedit/report/reportCenter.do. The manipulation of the argument fvID/catID leads to sql injection.
This vulnerability is handled as CVE-2025-2117. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-2116 | Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System File Protocol imageProxy.do server-side request forgery
9 months 1 week ago
A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /newsedit/newsedit/xy/imageProxy.do of the component File Protocol Handler. The manipulation of the argument xyImgUrl leads to server-side request forgery.
This vulnerability is known as CVE-2025-2116. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #506948: Quantico Tecnologia PRMV 6.48 Time Based Blind SQL Injection [Accepted]
9 months 1 week ago
Submit #506948 / VDB-299013
y4g0
CVE-2025-2115 | zzskzy Warehouse Refinement Management System 3.1 /AcceptZip.ashx ProcessRequest file unrestricted upload
9 months 1 week ago
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload.
This vulnerability is traded as CVE-2025-2115. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #508302: Beijing Founder Electronics Co., Ltd. Founder Enjoys All-Media Acquisition and Editing System V3.0 SQL Injection [Accepted]
9 months 1 week ago
Submit #508302 / VDB-299012
0menc
Submit #503719: Beijing Founder Electronics Co., Ltd. Founder Enjoys All-Media Acquisition and Editing System V3.0 Server-Side Request Forgery [Accepted]
9 months 1 week ago
Submit #503719 / VDB-299011
0menc
CVE-2025-2114 | Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7 Reset Password Interface OperatorStop.asp OperId improper authorization
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This issue affects some unknown processing of the file /WebPages/Adm/OperatorStop.asp of the component Reset Password Interface. The manipulation of the argument OperId leads to improper authorization.
The identification of this vulnerability is CVE-2025-2114. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #506655: www.zzskzy.com Warehouse refinement management system v3.1 RCE [Accepted]
9 months 1 week ago
Submit #506655 / VDB-299010
heihei_XZ
CVE-2024-13908 | bestwebsoft SMTP Plugin up to 1.1.9 on WordPress save_options unrestricted upload
9 months 1 week ago
A vulnerability classified as critical was found in bestwebsoft SMTP Plugin up to 1.1.9 on WordPress. This vulnerability affects the function save_options. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-13908. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-11087 | cyberlord92 miniOrange Social Login and Register Pro Addon Plugin improper authentication
9 months 1 week ago
A vulnerability classified as critical has been found in cyberlord92 miniOrange Social Login and Register Pro Addon Plugin up to 200.3.9 on WordPress. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2024-11087. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2113 | AT Software Solutions ATSVD up to 3.4.1 Esqueceu a senha txtCPF sql injection
9 months 1 week ago
A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Esqueceu a senha. The manipulation of the argument txtCPF leads to sql injection.
This vulnerability is handled as CVE-2025-2113. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #506591: Shenzhen Sixun Software Co., Ltd Sixun Shanghui 7 Group Business Management System Sixun Shanghui 7 unauthorized [Accepted]
9 months 1 week ago
Submit #506591 / VDB-299009
yaozhangYiqiyin
CVE-2025-2112 | user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4 MediaInfoService.java getMediaLisByFilter typeId sql injection
9 months 1 week ago
A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declared as critical. Affected by this vulnerability is the function getMediaLisByFilter of the file cn/javaex/yaoqishan/service/media_info/MediaInfoService.java. The manipulation of the argument typeId leads to sql injection.
This vulnerability is known as CVE-2025-2112. The attack can be launched remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #506341: AT Software Solutions ATSVD < 3.4.2 Blind Boolean-Based SQL Injection [Accepted]
9 months 1 week ago
Submit #506341 / VDB-299006
y4g0
Submit #506085: user-xiangpeng yaoqishan master SQL Injection [Accepted]
9 months 1 week ago
Submit #506085 / VDB-299005
xiaolian-11
CVE-2024-13825 | Email Keep Plugin up to 1.1 on WordPress cross site scripting
9 months 1 week ago
A vulnerability was found in Email Keep Plugin up to 1.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13825. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1481 | mandooox Shortcode Cleaner Lite Plugin up to 1.0.9 on WordPress download_backup authorization
9 months 1 week ago
A vulnerability was found in mandooox Shortcode Cleaner Lite Plugin up to 1.0.9 on WordPress and classified as problematic. This issue affects the function download_backup. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2025-1481. The attack may be initiated remotely. There is no exploit available.
vuldb.com