Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Page.Preview.Js.
This issue affects MediaWiki: from * before 1.43.6, 1.44.3, 1.45.1.
Affected products
MediaWiki
<1.43.6, 1.44.3, 1.45.1
Matching in nixpkgs
pkgs.mediawiki
Collaborative editing software that runs Wikipedia
Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation
Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Methods Name field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in version 5.5.2.
Affected products
commerce
==>= 5.0.0, < 5.5.2
Matching in nixpkgs
pkgs.python312Packages.azure-mgmt-commerce
This is the Microsoft Azure Commerce Management Client Library
list=allrevisions can be used to bypass Extension:Lockdown
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php.
This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Affected products
MediaWiki
<1.39.16, 1.43.6, 1.44.3, 1.45.1
Matching in nixpkgs
pkgs.mediawiki
Collaborative editing software that runs Wikipedia
Moodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
Affected products
moodle
<4.5.8
<5.1.1
<4.4.12
<4.1.22
<5.0.4
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Zone (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
Affected products
commerce
==>= 5.0.0, < 5.5.2
==>= 4.0.0-RC1, < 4.10.1
Matching in nixpkgs
pkgs.python312Packages.azure-mgmt-commerce
This is the Microsoft Azure Commerce Management Client Library
Stored XSS through a system message in Special:ApiSandbox
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.
This issue affects MediaWiki: from * before 1.44.3, 1.45.1.
Affected products
MediaWiki
<1.44.3, 1.45.1
Matching in nixpkgs
pkgs.mediawiki
Collaborative editing software that runs Wikipedia
[qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.
Moodle: moodle: data exposure of user identifiers in urls
A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.
Affected products
moodle
<4.5.8
<5.1.1
<4.4.12
<4.1.22
<5.0.4
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.
Affected products
PMB
==5.6
Matching in nixpkgs
pkgs.pmbootstrap
Sophisticated chroot/build/flash tool to develop and install postmarketOS
Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.
Affected products
moodle
<4.5.8
<5.1.1
<4.4.12
<4.1.22
<5.0.4
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP