Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Antón Ortigueira

#17143of 53,633
15.6Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2024-11657
9.1
2024-04-08
Abrhilsoft · Abrhilsoft Employee'S Portal · CVE-2022-43216
**Name of the Vulnerable Software and Affected Versions** AbrhilSoft Employee's Portal versions prior to 5.6.2 **Description** The issue is related to a SQL injection vulnerability found in the login page. This vulnerability can potentially be exploited to extract or modify sensitive data from the database. **Recommendations** For versions prior to 5.6.2, update to version 5.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation. Avoid using user-input data directly in SQL queries until the issue is resolved.
PT-2021-11805
6.5
2021-02-18
Unknown · Endalia Selection Portal · CVE-2020-35577
Name of the Vulnerable Software and Affected Versions: Endalia Selection Portal versions prior to 4.205.0 Description: The issue allows any authenticated user to download every file uploaded to the platform by changing the value of the `file identifier` (also known as CommonDownload identification number). This is due to an Insecure Direct Object Reference (IDOR). Recommendations: For versions prior to 4.205.0, update to version 4.205.0 or later to resolve the issue. As a temporary workaround, consider restricting access to file downloads to minimize the risk of exploitation.