Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Benmalek Aymen

#21503of 53,638
11.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-21196
5.4
2024-02-20
Mondula Gmbh · Multi Step Form · CVE-2024-25905
**Name of the Vulnerable Software and Affected Versions** Mondula GmbH Multi Step Form versions 1.7.18 and earlier **Description** The issue is a Cross-Site Request Forgery (CSRF) vulnerability. This type of vulnerability allows an attacker to trick a user into performing unintended actions on a web application that the user is authenticated to. **Recommendations** For versions 1.7.18 and earlier, update to a version that is not affected by this issue, if available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-31663
5.9
2023-12-21
Mondula Gmbh · Multi Step Form · CVE-2023-50832
**Name of the Vulnerable Software and Affected Versions** Mondula GmbH Multi Step Form versions 1.7.13 and earlier **Description** The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. This allows for Stored XSS attacks. **Recommendations** For versions 1.7.13 and earlier, update to a version later than 1.7.13 to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.