CVE-2022-2725
published 2022-08-09CVE-2022-2725: A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.42%
33.8th percentile
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | company_website_cms | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cisa9.8CRITICAL
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2cg-g8m3-mhp8: A vulnerability was found in SourceCodester Company Website CMS
ghsa_unreviewed·2022-08-10
CVE-2022-2725 [MEDIUM] CWE-79 GHSA-f2cg-g8m3-mhp8: A vulnerability was found in SourceCodester Company Website CMS
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this vulnerability.
Red Hat
kernel: netfilter: use get_random_u32 instead of prandom
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49698 [HIGH] CWE-362 kernel: netfilter: use get_random_u32 instead of prandom
kernel: netfilter: use get_random_u32 instead of prandom
In the Linux kernel, the following vulnerability has been resolved:
netfilter: use get_random_u32 instead of prandom
bh might occur while updating per-cpu rnd_state from user context,
ie. local_out path.
BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725
caller is nft_ng_random_eval+0x24/0x54 [nft_numgen]
Call Trace:
check_preemption_disabled+0xde/0xe0
nft_ng_random_eval+0x24/0x54 [nft_numgen]
Use the random driver instead, this also avoids need for local prandom
state. Moreover, prandom now uses the random driver since d4150779e60f
("random32: use real rng for non-deterministic randomness").
Based on earlier patch from Pablo Neira.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel
CISA
Oracle WebLogic Server, Injection
cisa·2022-01-10·CVSS 9.8
CVE-2019-2725 [CRITICAL] CWE-74 Oracle WebLogic Server, Injection
Vulnerability: Oracle WebLogic Server, Injection
Affected: Oracle WebLogic Server
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2725
Remediation Due Date: 2022-07-10
No detection rules found.
No public exploits indexed.
2022-08-09
Published