NVD disclosure day

Published threat advisories for November 25, 2022

CVE advisoryCRITICAL

CVE-2022-45207

Jeecg-boot SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the Jeecg-boot platform that could allow unauthorized data access or modification. The issue is present in the `updateNullByEmptyString` component and can be reached via network requests without authentication. This could lead to manipulation of database queries, potentially impa

CVE advisoryCRITICAL

CVE-2022-45206

Jeecg-boot SQL Injection Vulnerability in Duplicate Check Component.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Jeecg-boot platform, potentially allowing unauthenticated attackers to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or deletion of system data. The affected component is part of the platform's core functionality, often exposed

CVE advisoryCRITICAL

CVE-2022-37721

PyroCMS 3.9 Stored XSS Allows Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability in PyroCMS allows a low-privileged user to inject malicious code into blog posts, potentially leading to administrator account takeover or privilege escalation. This issue is relevant if PyroCMS is deployed and content management is exposed.

CVE advisoryCRITICAL

CVE-2022-37720

Orchard CMS Cross Site Scripting Leading to Admin Account Takeover

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Orchard CMS is vulnerable to cross-site scripting, allowing low-privileged users to inject malicious code into blog posts. When viewed, this code can execute in a victim's browser, potentially leading to admin account takeover or privilege escalation. It's important to determine if this technology is in use and exposed