Skip to content

Instantly share code, notes, and snippets.

@aliceicl
aliceicl / CVE-2022-30335.txt
Last active May 9, 2022 16:26
Findings for CVE-2022-30335
[Product Description]
Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
------------------------------------------
[Vulnerability Type]
SQL Injection
------------------------------------------
[Vendor of Product]
Wealth Management System Limited
@aliceicl
aliceicl / CVE-2019-18411.txt
Last active November 3, 2019 18:00
Findings for CVE-2019-18411
[Product Description]
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are
attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone,
unintentionally. As a consequence, attackers could use the reset password function and control the system to send the
authentication code back to the channel that the attackers own.
------------------------------------------
[Vulnerability Type]
Cross Site Request Forgery (CSRF)