Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yuanshen

#16500de 53,635
16.3CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2023-31486
9.8
2023-09-16
Lmxcms · Lmxcms · CVE-2023-5017
**Name of the Vulnerable Software and Affected Versions** lmxcms versions up to 1.41 **Description** A critical issue affects some unknown functionality of the file admin.php. The manipulation of the `lid` argument leads to SQL injection. The vendor was contacted about this disclosure but did not respond. **Recommendations** For versions up to 1.41, as a temporary workaround, consider restricting access to the admin.php file until a patch is available. Avoid using the `lid` argument in the affected functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2023-31404
6.5
2023-09-15
Unknown · Bettershop Laiketui · CVE-2023-4988
**Name of the Vulnerable Software and Affected Versions** Bettershop LaikeTui (affected versions not specified) **Description** A problematic issue was found in Bettershop LaikeTui, affecting the file index.php?module=system&action=uploadImg. The manipulation of the `imgFile` argument leads to unrestricted upload. This issue can be initiated remotely. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.