NVD disclosure day

Published threat advisories for September 18, 2024

CVE advisoryCRITICAL

CVE-2024-6877

Eliz Software Panel Cross-Site Scripting Vulnerability Advisory

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Eliz Software Panel allows for cross-site scripting, potentially impacting data and user sessions. The risk arises from improper input handling, enabling attackers to inject malicious code via user interaction. This could lead to unauthorized actions and data compromise for affected organizations.

CVE advisoryCRITICAL

CVE-2024-5959

Eliz Software Panel Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A stored cross-site scripting vulnerability in Eliz Software Panel can allow attackers to inject malicious scripts into web pages, potentially leading to unauthorized data access or content manipulation. This poses a risk to affected organizations by enabling script execution within the panel, which can impact user ses

CVE advisoryCRITICAL

CVE-2024-5958

Eliz Software Panel SQL Injection Vulnerability Allows Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Eliz Software Panel allows unauthorized command execution via SQL injection. This impacts systems running the affected panel, creating risks to data and operational integrity for organizations. Attackers can exploit this flaw without authentication, leading to potential data compromise and system dis