CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117556606
