Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Echox1O

#17793of 53,633
15.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2021-10393
9.8
2021-08-26
Unknown · Thinkphp-Zcms · CVE-2020-19705
Name of the Vulnerable Software and Affected Versions: thinkphp-zcms as of 20190715 Description: The issue allows SQL injection via the "index.php?m=home&c=message&a=add" API endpoint. This could potentially lead to unauthorized access to sensitive data. Recommendations: For thinkphp-zcms as of 20190715, avoid using the "index.php?m=home&c=message&a=add" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2018-13996
5.3
2018-09-23
Publiccms · Publiccms · CVE-2018-17368
**Name of the Vulnerable Software and Affected Versions** PublicCMS version 4.0.180825 **Description** An issue in PublicCMS makes it easier to conduct brute-force attacks due to different response lengths for invalid login attempts, depending on whether the username is valid. **Recommendations** For PublicCMS version 4.0.180825, at the moment, there is no information about a newer version that contains a fix for this vulnerability.