Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Anthony Goyette

Researcher fromChevron
#18422of 53,638
14.7Total CVSS
Vulnerabilities · 2
High
2
PT-2023-15611
7.2
2023-11-06
Softing · Smartlink Sw-Ht · CVE-2022-48192
**Name of the Vulnerable Software and Affected Versions** Softing smartLink SW-HT versions prior to 1.30 **Description** The issue allows an attacker to execute a dynamic script, such as JavaScript or VBScript, in the context of the application. This is a Cross-site Scripting vulnerability. **Recommendations** For versions prior to 1.30, update to version 1.30 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.
PT-2023-15612
7.5
2023-11-06
Softing · Smartlink Sw-Ht · CVE-2022-48193
**Name of the Vulnerable Software and Affected Versions** Softing smartLink SW-HT versions prior to 1.30 **Description** The issue concerns the use of weak ciphers during secure communication via SSL in the affected software. This could potentially compromise the security of the communication. **Recommendations** For versions prior to 1.30, update to version 1.30 or later to resolve the issue. As a temporary workaround, consider disabling the use of weak ciphers in SSL communication until a patch is available. Restrict access to sensitive data transmitted over SSL to minimize the risk of exploitation.