Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

G37Sys73M

#17706of 53,624
15.2Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2023-21313
9.8
2023-05-16
Unknown · Idurar Erp/Crm · CVE-2023-27742
**Name of the Vulnerable Software and Affected Versions** IDURAR ERP/CRM version 1 **Description** The issue is related to a SQL injection vulnerability. It affects the `/api/login` component. **Recommendations** For IDURAR ERP/CRM version 1, consider restricting access to the `/api/login` endpoint until a patch is available. As a temporary workaround, avoid using sensitive data in the login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-14810
5.4
2023-01-30
Unknown · Cloudschool · CVE-2022-46087
**Name of the Vulnerable Software and Affected Versions** CloudSchool version 3.0.1 **Description** The issue allows a normal user to steal session cookies of admin users through a notification received by the admin user, exploiting a Cross Site Scripting (XSS) weakness. **Recommendations** For CloudSchool version 3.0.1, update to a version that includes a fix for this issue, as no specific workaround is provided in the available information.