Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Laolisafe

#46866de 53,638
5.4CVSS total
Vulnerabilidades · 1
PT-2018-14916
5.4
2018-11-17
Kimsq · Kimsq Rb · CVE-2018-19324
**Name of the Vulnerable Software and Affected Versions** kimsQ Rb version 2.3.0 **Description** The issue allows for XSS via the second input field to the "/?r=home&mod=mypage&page=info" API endpoint. **Recommendations** For version 2.3.0, consider restricting access to the "/?r=home&mod=mypage&page=info" API endpoint until a patch is available. As a temporary workaround, avoid using the second input field in this endpoint to minimize the risk of exploitation.