Di seguito una lista di advisory di sicurezza e CVEs scoperte durante attività di ricerca indipendente e security assessment. Clicca su una voce per espandere i dettagli.
CVE-2025-46320 FileMaker Server — Reflected XSS 2025-12-16 8.8 High
+
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.
CVE-2025-46296 FileMaker Server — Authorization Bypass 2025-12-16 5.4 Medium
+
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs.
CVE-2025-46294 FileMaker WebDirect — IIS Misconfiguration 2025-12-16 5.3 Medium
+
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character.
CVE-2023-0581 PrivateContent — Protection Mechanism Bypass 2023-01-30 5.3 Medium
+
The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthenticated attackers to bypass any login restrictions that may prevent a brute force attack.
Attività di Ricerca
Puoi trovarmi sulle seguenti piattaforme: