NA - CVE-2024-47947 - Due to missing input sanitization, an attacker...
Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the...
NA - CVE-2024-54119 - Cross-process screen stack vulnerability in the...
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
NA - CVE-2024-28143 - The password change function at /cgi/admin.cgi...
The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a...
NA - CVE-2024-28144 - An attacker who can spoof the IP address and...
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web...
NA - CVE-2024-28145 - An unauthenticated attacker can perform an SQL...
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value...
NA - CVE-2024-28146 - The application uses several hard-coded...
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database...
NA - CVE-2024-50584 - An authenticated attacker with the user/role...
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter...
Medium - CVE-2024-49071 - Improper authorization of an index that...
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.