Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mortalwangxin

#14484de 53,635
18.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2023-19495
9.8
2023-01-31
Unknown · Forget Heart Message Box · CVE-2023-24241
**Name of the Vulnerable Software and Affected Versions** Forget Heart Message Box version 1.1 **Description** A SQL injection issue was discovered via the `name` parameter at the "/admin/loginpost.php" API endpoint. This allows for potential exploitation. No information is available regarding the estimated number of affected devices or real-world incidents. **Recommendations** For Forget Heart Message Box version 1.1, consider restricting access to the "/admin/loginpost.php" API endpoint until a fix is available. As a temporary workaround, avoid using the `name` parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-19838
8.8
2023-01-31
Unknown · Forget Heart Message Box · CVE-2023-24956
**Name of the Vulnerable Software and Affected Versions** Forget Heart Message Box version 1.1 **Description** A SQL injection issue was discovered in Forget Heart Message Box via the `name` parameter at the "/cha.php" API endpoint. **Recommendations** For Forget Heart Message Box version 1.1, consider restricting access to the `/cha.php` endpoint or sanitizing the `name` parameter to prevent SQL injection attacks until a patch is available.