Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Carlcj

#20592of 53,624
12.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2018-9603
4.8
2018-12-27
Peel · Peel Shopping · CVE-2018-1000887
Name of the Vulnerable Software and Affected Versions: peel-shopping 9 1 0 version Description: The issue allows an authenticated user to inject java script code in the `Site Name EN` parameter, resulting in a Cross Site Scripting (XSS) issue. This can be exploited if the malicious user has access to the administration account. Recommendations: For peel-shopping 9 1 0 version, avoid using the `Site Name EN` parameter until the issue is resolved. As a temporary workaround, consider restricting access to the administration account to minimize the risk of exploitation.
PT-2018-9605
7.5
2018-12-27
Frontaccounting · Frontaccounting · CVE-2018-1000890
Name of the Vulnerable Software and Affected Versions: FrontAccounting version 2.4.5 Description: The issue concerns a Time Based Blind SQL Injection that affects the `filterType` parameter in the "/attachments.php" API endpoint. This can potentially allow an attacker to access the entire database of the application. Recommendations: For FrontAccounting version 2.4.5, consider restricting access to the "/attachments.php" endpoint until a patch is available. As a temporary workaround, avoid using the `filterType` parameter in the affected endpoint to minimize the risk of exploitation.