Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fschuckert

#20629of 53,624
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-17110
6.1
2021-02-21
Emoncms · Emoncms · CVE-2021-26716
**Name of the Vulnerable Software and Affected Versions** Emoncms versions 10.2.7 and earlier **Description** The issue allows for XSS via the `node` parameter in the Modules/input/Views/schedule.php file. **Recommendations** For versions 10.2.7 and earlier, as a temporary workaround, consider restricting access to the `schedule.php` file until a patch is available. Avoid using the `node` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-20063
6.1
2021-01-27
Dzzoffice · Dzzoffice · CVE-2021-3318
**Name of the Vulnerable Software and Affected Versions** DzzOffice versions 2.02.1 and earlier **Description** The issue allows for XSS via the `editorid` parameter in the "attach/ajax.php" endpoint. **Recommendations** For DzzOffice versions 2.02.1 and earlier, as a temporary workaround, consider restricting access to the "attach/ajax.php" endpoint until a patch is available. Avoid using the `editorid` parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.