Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Johannes Lauinger

#20973of 53,633
11.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-38930
6.5
2024-11-28
Siempelkamp · Umweltoffice · CVE-2024-8308
Name of the Vulnerable Software and Affected Versions: Web Application (affected versions not specified) Description: A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data, which allows the exfiltration of all data. This occurs because the application does not correctly handle input data from HTTP requests. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-15901
5.4
2021-07-12
WordPress · Admin Columns · CVE-2021-24365
**Name of the Vulnerable Software and Affected Versions** Admin Columns WordPress plugin Free versions prior to 4.3.2 Admin Columns WordPress plugin Pro versions prior to 5.5.2 **Description** The issue allows configuration of individual columns for tables, with a column type of "Custom Field" enabling the choice of an arbitrary database column to display in the table. However, there is no escaping applied to the contents of "Custom Field" columns. **Recommendations** For Admin Columns WordPress plugin Free versions prior to 4.3.2, update to version 4.3.2 or later. For Admin Columns WordPress plugin Pro versions prior to 5.5.2, update to version 5.5.2 or later.