Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Faiz Ahmed Zaidi

Pesquisador deProvensec LLC
#23827de 53,639
9.9CVSS total
Vulnerabilidades · 2
Média
2
PT-2017-19068
5.4
2017-07-17
Blackcat · Blackcat Cms · CVE-2017-9609
**Name of the Vulnerable Software and Affected Versions** Blackcat CMS version 1.2 **Description** A cross-site scripting (XSS) issue allows remote authenticated users to inject arbitrary web script or HTML via the `map language` parameter to "backend/pages/lang settings.php". **Recommendations** For Blackcat CMS version 1.2, avoid using the `map language` parameter in the "backend/pages/lang settings.php" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the backend/pages/lang settings.php page to minimize the risk of exploitation.
PT-2017-18305
4.5
2017-05-16
Admidio · Admidio · CVE-2017-8382
**Name of the Vulnerable Software and Affected Versions** admidio version 3.2.8 **Description** The issue allows for Cross-Site Request Forgery (CSRF) in the `adm program/modules/members/members function.php` file, which can lead to the deletion of arbitrary user accounts. **Recommendations** For admidio version 3.2.8, consider disabling the `members function.php` file or restricting access to it until a patch is available to prevent the deletion of user accounts.