Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alexandre Labbe

Researcher fromA1 Digital International
#21228of 53,608
11.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-5011
6.4
2024-07-04
Vmware · Vmware Cloud Director Availability · CVE-2024-22277
Name of the Vulnerable Software and Affected Versions: VMware Cloud Director Availability (affected versions not specified) Description: The issue is related to an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks, potentially allowing for cross-site scripting (XSS) attacks by injecting malicious HTML tags. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-4789
5.3
2024-01-08
Vmware · Vmware Cloud Director Object Storage Extension · CVE-2024-22276
Name of the Vulnerable Software and Affected Versions: VMware Cloud Director Object Storage Extension (affected versions not specified) Description: The issue concerns an Insertion of Sensitive Information, where a malicious actor with adjacent access to web/proxy server logging may obtain sensitive information from logged URLs. This could allow a remote attacker to gain unauthorized access to protected information due to insufficient protection of service data. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.