Weekly digest
Week 10, 2023 (6–12 Mar)
10 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 1 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mayurik was the most-affected vendor with 5.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-27205Critical· 9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
CVE-2023-27204Critical· 9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
CVE-2023-27203Critical· 9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
CVE-2023-27202Critical· 9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
CVE-2023-22432Medium· 6.1PoCOpen redirect in web2py
Open redirect in web2py
CVE-2023-27522High· 7.5httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
CVE-2017-20182Medium· 6.1Cross-site Scripting in django-ajax-utilities
Cross-site Scripting in django-ajax-utilities
CVE-2023-27206Medium· 6.1A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
Most-affected vendors
By CVEs published in the period.