MidnightBSD

Advisories for genetechsolutions

CVE-2013-4954 LOW

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
genetechsolutions pie-register 1.2.6
genetechsolutions pie-register 1.2.9
genetechsolutions pie-register 1.1.3
genetechsolutions pie-register 1.1.9
genetechsolutions pie-register 1.1.7
genetechsolutions pie-register 1.2.8
genetechsolutions pie-register 1.1.8
genetechsolutions pie-register 1.1.6
genetechsolutions pie-register 1.2.4
genetechsolutions pie-register 1.2.3
genetechsolutions pie-register 1.2.7
genetechsolutions pie-register 1.1.2
genetechsolutions pie-register 1.2.1
genetechsolutions pie-register *
genetechsolutions pie-register 1.1.5
genetechsolutions pie-register 1.1.1
genetechsolutions pie-register 1.2.91
genetechsolutions pie-register 1.2.2
genetechsolutions pie-register 1.2.0
genetechsolutions pie-register 1.0.1
CVE-2014-8802 MEDIUM

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
genetechsolutions pie_register *
CVE-2015-7377 MEDIUM

Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
genetechsolutions pie_register *
CVE-2015-7682 MEDIUM

Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
genetechsolutions pie_register *
CVE-2018-10969 HIGH

SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
genetechsolutions pie_register *