CVE-2019-9058

CVSS v3 Score
7.2
High
CVSS v2 Score
6.5
Medium

Vulnerability Description

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

CVSS:7.2(High)

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to c...

CVSS:7.2(High)

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.

CVSS:7.2(High)

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.

CVSS:7.2(High)

This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.

CVSS:7.2(High)

pathval before version 1.1.1 is vulnerable to prototype pollution.

CVSS:7.2(High)

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command...