ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-46347
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection.

In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

NVD description · AI analysis pending
9.850%
  • ndkdesign ndk steppingpack
CVE-2020-12699
+3 in the same advisory: …12697 …12700 …12698
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.

NVD description · AI analysis pending
6.1
group max
<1%
  • dkd direct mail
CVE-2019-16698
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissio

The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.

NVD description · AI analysis pending
4.3<1%
  • dkd direct mail