Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
Category Archives: Advisories
CVE-2021-36863 (quiz_and_survey_master)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-38217 (semcms)
CVE-2021-36858 (testimonials)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
xerces-c-3.2.3-5.el8
FEDORA-EPEL-2022-fac3491880
Packages in this update:
xerces-c-3.2.3-5.el8
Update description:
Update to 3.2.3 (#1788475)
CVE-2021-37782 (employee_record_management_system)
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
CVE-2021-35388
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-37781 (employee_record_management_system)
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
CVE-2021-35387
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
ghc-cmark-gfm-0.2.5-1.fc36
FEDORA-2022-6bcee2cc93
Packages in this update:
ghc-cmark-gfm-0.2.5-1.fc36
Update description:
updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209