CVE-2023-42250
- EPSS 0.24%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 17.04.2025 16:34:15
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.
CVE-2023-42249
- EPSS 0.24%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 17.04.2025 16:34:22
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.
CVE-2023-42248
- EPSS 0.14%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 17.04.2025 16:34:29
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
CVE-2023-42247
- EPSS 0.18%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 17.04.2025 16:34:34
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.
CVE-2023-42246
- EPSS 0.18%
- Veröffentlicht 13.01.2025 22:15:13
- Zuletzt bearbeitet 17.04.2025 16:34:38
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.
CVE-2023-42238
- EPSS 0.13%
- Veröffentlicht 13.01.2025 22:15:12
- Zuletzt bearbeitet 17.04.2025 16:35:05
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.
CVE-2023-42245
- EPSS 0.18%
- Veröffentlicht 13.01.2025 22:15:12
- Zuletzt bearbeitet 17.04.2025 16:34:42
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.
CVE-2023-42244
- EPSS 0.13%
- Veröffentlicht 13.01.2025 22:15:12
- Zuletzt bearbeitet 17.04.2025 16:34:45
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.
CVE-2023-42243
- EPSS 0.16%
- Veröffentlicht 13.01.2025 22:15:12
- Zuletzt bearbeitet 17.04.2025 16:34:49
In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.
CVE-2023-42242
- EPSS 0.09%
- Veröffentlicht 13.01.2025 22:15:12
- Zuletzt bearbeitet 17.04.2025 16:34:52
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.