offsecin/bugsdisclose

offsecin/bugsdisclose

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.

8.8 HIGH6.5 MEDIUM

Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

5.4 MEDIUM3.5 LOW

Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

8.8 HIGH6.8 MEDIUM

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.