Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Montala vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ResourceSpace 8.6 SQL Injection via watched_searches.php

ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials.

CWE-89Apr 5, 2026
CVSS8.8v4.0EPSS0.422%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

montala resourcespace Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's browser.

CWE-79Nov 15, 20211 related artifact
CVSS6.1v3.1EPSS77.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX