Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Debangshu Kundu

#20113of 53,633
12.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-20511
6.5
2024-05-17
Unknown · The Events Calendar Bookit · CVE-2024-24715
**Name of the Vulnerable Software and Affected Versions** The Events Calendar BookIt versions 2.4.0 and earlier **Description** The issue is related to improper validation of specified quantity in input, allowing manipulation of hidden fields. This can be exploited to potentially alter or access unauthorized data. **Recommendations** For versions 2.4.0 and earlier, update to a version later than 2.4.0 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-15075
6.4
2024-01-03
WordPress · Foogallery · CVE-2023-6747
**Name of the Vulnerable Software and Affected Versions** FooGallery plugin for WordPress versions up to, and including, 2.3.3 **Description** The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes due to insufficient input sanitization and output escaping. This allows contributors and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. **Recommendations** For FooGallery plugin for WordPress versions up to, and including, 2.3.3, update to a version later than 2.3.3 to resolve the issue. As a temporary workaround, consider restricting access to the custom attributes feature to minimize the risk of exploitation.