Medium
CVSS: 6.1
Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
Critical
CVSS: 9.8
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.
Critical
CVSS: 9.8
A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.
Critical
CVSS: 9.3
A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM f…