Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aditya Vyawahare

#21822of 53,633
10.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-28757
4.8
2024-07-02
WordPress · Eazydocs · CVE-2024-3999
**Name of the Vulnerable Software and Affected Versions** EazyDocs WordPress plugin versions prior to 2.5.0 **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This is possible because some settings are not properly sanitised and escaped, and this vulnerability can be exploited even when the unfiltered html capability is disallowed, for example in a multisite setup. **Recommendations** For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the ability of high privilege users to modify plugin settings until the update is applied.
PT-2020-14862
6.1
2020-08-10
Saint · Saint Security Suite · CVE-2020-16275
**Name of the Vulnerable Software and Affected Versions** SAINT Security Suite versions 8.0 through 9.8.20 **Description** A cross-site scripting (XSS) issue in the Credential Manager component could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. **Recommendations** For versions 8.0 through 9.8.20, update to a version that contains a fix for this issue to prevent arbitrary script execution.