CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
Publication date: Tue, 29 Apr 2025 16:05:00 +0000
Cyber News related to CVE-2025-23178
CVE-2025-23178 - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints ...
8 months ago
CVE-2022-23178 - An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. ...
2 years ago
CVE-2020-23178 - An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user. ...
4 years ago
CVE-2021-23178 - Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be ...
2 years ago
CVE-2024-23178 - An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message. ...
2 years ago Tenable.com