CVE-2023-2943

CVSS v3 Score
4.6
Medium

Vulnerability Description

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVSS:4.5(Medium)

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a templ...

CWE-942005
CVSS:4.7(Medium)

Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.

CWE-942024
CVSS:4.7(Medium)

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command...

CWE-942024
CVSS:4.4(Medium)

IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.

CWE-942017
CVSS:4.4(Medium)

Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

CWE-942021
CVSS:4.4(Medium)

Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is exploited, a non-administrative user of the Mac where the product is installed ma...

CWE-942023