Web Application Detections Published in October 2024

Hitesh Kadu

In October, Qualys released QIDs targeting vulnerabilities in several widely used software products, including WordPress, Zohocorp ManageEngine Endpoint, Lobe Chat, Ivanti Virtual Traffic Manager (vTM), Traefik, Nginx Proxy Manager, Harbor, Haproxy, SolarWinds Access Rights Manager (ARM), Cacti, Ivanti Endpoint Manager Mobile (EPMM), JetBrains TeamCity, Palo Alto Networks Expedition, Progress Telerik Report Server, Zimbra, Oracle WebLogic Server, Apache Solr, FlatPress CMS, pgAdmin, Grafana, pfSense, SolarWinds Web Help Desk, Ivanti Avalanche, ReCrystallize Server, Joomla!, and PHP. The QIDs released to detect the vulnerabilities in the frameworks above are listed below. Details about the following QIDs can be found in our knowledge base. Please review reports of the scanned applications for these detections and, if any are identified follow the steps provided in the knowledge base to ensure applications are protected against the reported vulnerabilities.

QIDTitle
152202Zohocorp ManageEngine Endpoint Central Incorrect Authorization Vulnerability (CVE-2024-38868)
152206WordPress Delicious Recipe Plugin: Arbitrary File Movement and Reading Vulnerability (CVE-2024-7626)
152207WordPress Simple Spoiler Plugin: Arbitrary Shortcode Execution Vulnerability (CVE-2024-8479)
152209WordPress PropertyHive Plugin: Cross-Site Request Forgery Vulnerability (CVE-2024-8490)
152210WordPress Share This Image Plugin: Open Redirect Vulnerability (CVE-2024-8761)
152215WordPress infolinks Ad Wrap Plugin: Cross-Site Request Forgery Vulnerability (CVE-2024-8044)
152216WordPress Bit File Manager Plugin: Arbitrary File Uploads Vulnerability (CVE-2024-7770)
152224WordPress Logo Manager For Enamad Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2024-5170)
152247Lobe Chat Server-Side Request Forgery Vulnerability (CVE-2024-47066)
152248WordPress Jupiter X Core Plugin: Arbitrary File Upload Vulnerability (CVE-2024-7772)
152250WordPress Advanced File Manager Plugin: Local JavaScript File Inclusion Vulnerability (CVE-2024-8704)
152251WordPress Visitors Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2022-4541)
152252WordPress Product Enquiry for WooCommerce Plugin: PHP Object Injection Vulnerability (CVE-2024-8922)
152254WordPress Jupiter X Core Plugin: Authentication Bypass Vulnerability (CVE-2024-7781)
152255WordPress Advanced File Manager Plugin: Arbitrary File Upload Vulnerability (CVE-2024-8126)
152256WordPress Eventin Plugin: Local File Inclusion Vulnerability (CVE-2024-7149)
152257Ivanti Virtual Traffic Manager (vTM) Authentication Bypass Vulnerability (CVE-2024-7593)
152259WordPress Wechat Social Login Plugin: Authentication Bypass Vulnerability (CVE-2024-9106)
152260WordPress Wechat Social Login Plugin: Arbitrary File Upload Vulnerability (CVE-2024-9108)
152261Traefik HTTP Client Header Manipulation Vulnerability (CVE-2024-45410)
152262WordPress WP Easy Gallery Plugin: Time-based SQL Injection Vulnerability (CVE-2024-9018)
152263WordPress Unseen Blog Theme: PHP Object Injection Vulnerability (CVE-2024-7432)
152264WordPress Empowerment Theme: PHP Object Injection Vulnerability (CVE-2024-7433)
152266WordPress KB Support Plugin: Unauthorized Modification and Loss of Data Vulnerability (CVE-2024-8548)
152268WordPress Broken Link Checker Plugin: Reflected Cross-Site Scripting Vulnerability (CVE-2024-8981)
152269Nginx Proxy Manager Command Injection Vulnerability (CVE-2024-46256)
152270Harbor Improper Privilege Management Vulnerability (CVE-2024-22278)
152271Haproxy Detected
152272WordPress WP Hotel Booking Plugin: Arbitrary File Upload Vulnerability (CVE-2024-7855)
152273WordPress Social Web Suite Plugin: Directory Traversal Vulnerability (CVE-2024-8352)
152274WordPress WPvivid Backup and Migration Plugin: Unauthenticated Sensitive Data Exposure Vulnerability (CVE-2024-7315)
152275SolarWinds Access Rights Manager (ARM) Insecure Deserialization Remote Code Execution (RCE) Vulnerability (CVE-2024-28074)
152276SolarWinds Access Rights Manager (ARM) Authentication Bypass Vulnerability (CVE-2024-23465)
152277SolarWinds Access Rights Manager (ARM) Directory Traversal Vulnerabilities
152278SolarWinds Access Rights Manager (ARM) Remote Code Execution (RCE) Vulnerability (CVE-2024-23469)
152279SolarWinds Access Rights Manager (ARM) Remote Code Execution (RCE) Vulnerabilities (CVE-2024-23470, CVE-2024-23471)
152280SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerabilities (CVE-2024-23466,CVE-2024-23467)
152281Cacti Cross-Site Scripting Vulnerability (CVE-2024-43362)
152282Cacti Log Poisoning Vulnerability (CVE-2024-43363)
152283Cacti Cross-Site Scripting Vulnerability (CVE-2024-43364)
152284Cacti Cross-Site Scripting Vulnerability (CVE-2024-43365)
152286Ivanti Endpoint Manager Mobile (EPMM) Insecure Permissions Vulnerability (CVE-2024-7612)
152287JetBrains TeamCity Sensitive Credential Exposure Vulnerability (CVE-2024-47161)
152288JetBrains TeamCity Path Traversal Vulnerabilities (CVE-2024-47948, CVE-2024-47949)
152289JetBrains TeamCity Stored Cross-Site Scripting (XSS) Vulnerabilities (CVE-2024-47950, CVE-2024-47951)
152290WordPress LatePoint Plugin: SQL Injection Vulnerability (CVE-2024-8911)
152291WordPress LatePoint Plugin: Authentication Bypass Vulnerability (CVE-2024-8943)
152292Palo Alto Networks Expedition Admin Account Takeover Vulnerability (CVE-2024-5910)
152293Palo Alto Networks Expedition OS command injection vulnerability (CVE-2024-9463)
152294Palo Alto Networks Expedition OS Command Injection Vulnerability (CVE-2024-9464)
152295Palo Alto Networks Expedition SQL Injection Vulnerability (CVE-2024-9465)
152296Palo Alto Networks Expedition Cleartext Storage of Sensitive Information Vulnerability (CVE-2024-9466)
152297Palo Alto Networks Expedition Cross-site Scripting Vulnerability (CVE-2024-9467)
152298WordPress Pedalo Connector Plugin: Authentication Bypass Vulnerability (CVE-2024-9822)
152299WordPress Pretix Widget Plugin: Local File Inclusion Vulnerability (CVE-2024-9575)
152300Progress Telerik Report Server Insecure Type Resolution Vulnerability (CVE-2024-8015)
152301WordPress Users Masquerade Plugin: Authentication Bypass Vulnerability (CVE-2024-9522)
152302WordPress Shortcodes AnyWhere Plugin: Arbitrary Shortcode Execution Vulnerability (CVE-2024-9581)
152303WordPress File Upload Plugin: Path Traversal Vulnerability (CVE-2024-9047)
152304Zimbra Remote Code Execution (RCE) Vulnerability (CVE-2024-45519)
152305WordPress WP 2FA with Telegram Plugin: Authentication Bypass Vulnerability (CVE-2024-9687)
152306WordPress Bot for Telegram on WooCommerce Plugin: Sensitive Information Disclosure Vulnerability (CVE-2024-9821)
152307Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2024)
152308WordPress GutenKit Plugin: Arbitrary File Upload Vulnerability (CVE-2024-9234)
152309Apache Solr Authentication Bypass Vulnerability (CVE-2024-45216)
152310Apache Solr Insecure Default Initialization of Resource Vulnerability (CVE-2024-45217)
152311WordPress GiveWP Plugin: PHP Object Injection Vulnerability (CVE-2024-9634)
152312WordPress Hunk Companion Plugin: Unauthorized Plugin Installation/Activation Vulnerability (CVE-2024-9707)
152313WordPress Limb Gallery Plugin: Arbitrary File Upload Vulnerability (CVE-2024-49260)
152314FlatPress CMS: Sensitive Data Exposure in Cookies Vulnerability (CVE-2024-41290)
152315WordPress File Manager Plugin: Authentication Bypass Vulnerability (CVE-2018-25105)
152316WordPress ThemeGrill Demo Importer Plugin: Authentication Bypass Vulnerability (CVE-2020-36837)
152317pgAdmin Authentication Bypass Vulnerability (CVE-2024-9014)
152318Grafana Remote Code Execution Vulnerability (CVE-2024-9264)
152319pfSense Cross-site Scripting Vulnerability (CVE-2024-46538)
152321SolarWinds Web Help Desk Java Deserialization Remote Code Execution (RCE) Vulnerability (CVE-2024-28988)
152322WordPress WP Timetics Plugin: Insecure Direct Object Reference Vulnerability (CVE-2024-9263)
152323WordPress UserPro Plugin: Privilege Escalation Vulnerability (CVE-2024-9863)
152324Ivanti Avalanche Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-47008)
152325Ivanti Avalanche Path Traversal Vulnerabilities (CVE-2024-47009, CVE-2024-47010, CVE-2024-47011)
152326Ivanti Avalanche NULL pointer dereference Vulnerability (CVE-2024-47007)
152327Grafana Incorrect Permission Vulnerability (CVE-2024-8118)
152328ReCrystallize Server Authentication Bypass Vulnerability (CVE-2024-26331)
152329ReCrystallize Server Unrestricted File Upload Vulnerability (CVE-2024-28269)
152332WordPress AI Postpix Plugin: Arbitrary File Upload Vulnerability (CVE-2024-49671)
152334WordPress INK Official Plugin: Arbitrary File Upload Vulnerability (CVE-2024-49669)
152335WordPress Woocommerce Custom Profile Picture Plugin: Arbitrary File Upload Vulnerability (CVE-2024-49658)
154160Joomla! Core Cache Poisoning Vulnerability (CVE-2024-27185)
154161Joomla! Core Improper Access Control Vulnerability (CVE-2024-27187)
154162Joomla! Core Cross-Site Scripting Vulnerability (CVE-2024-40743)
154163Joomla! Core Cross-Site Scripting Vulnerability (CVE-2024-27186)
154164Joomla! Core Cross-Site Scripting Vulnerability (CVE-2024-26278)
154165Joomla! Core Cross-Site Scripting Vulnerability (CVE-2024-26279)
154166Joomla! Core Open Redirect Vulnerability (CVE-2024-27184)
520031PHP Erroneous Parsing of Multipart Form Data (CVE-2024-8925)
520032PHP Command Injection Vulnerability (CVE-2024-8926)
Share your Comments

Comments

Your email address will not be published. Required fields are marked *