Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sqlsec

#21834de 53,633
10.9CVSS total
Vulnerabilidades · 2
Média
2
PT-2018-13722
6.1
2018-09-09
Easycms · Easycms · CVE-2018-16759
**Name of the Vulnerable Software and Affected Versions** EasyCMS version 1.4 **Description** The issue concerns the removeXSS function in EasyCMS, which is vulnerable to XSS attacks via an onhashchange event. This is due to the function's inadequate handling of certain events, allowing malicious scripts to be executed. **Recommendations** For EasyCMS version 1.4, consider modifying the removeXSS function in App/Common/common.php to properly handle onhashchange events and prevent XSS attacks. As a temporary workaround, consider disabling the removeXSS function until a patch is available. Restrict access to the SearchAction.class.php module to minimize the risk of exploitation.
PT-2018-12266
4.8
2018-07-12
Catfish · Catfish Cms · CVE-2018-13999
**Name of the Vulnerable Software and Affected Versions** Catfish CMS version 4.7.9 **Description** The issue allows for XSS via the `editorValue` parameter in the "admin/Index/write.html" endpoint. This occurs when an article is posted by an administrator. **Recommendations** For Catfish CMS version 4.7.9, avoid using the `editorValue` parameter in the "admin/Index/write.html" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.