Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Johannes Rückert

#20083of 53,638
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-25364
7.5
2023-10-09
No Magic · Teamwork Cloud · CVE-2023-3589
**Name of the Vulnerable Software and Affected Versions** Teamwork Cloud versions No Magic Release 2021x through No Magic Release 2022x **Description** A Cross-Site Request Forgery (CSRF) vulnerability could allow an attacker to send a specifically crafted query to the server under certain conditions. **Recommendations** For versions No Magic Release 2021x through No Magic Release 2022x, consider implementing additional security measures to prevent CSRF attacks, such as validating request headers and using anti-CSRF tokens. As a temporary workaround, restrict access to sensitive server queries until a patch is available.
PT-2023-25359
5.4
2023-09-13
No Magic · Teamwork Cloud · CVE-2023-3588
**Name of the Vulnerable Software and Affected Versions** Teamwork Cloud versions No Magic Release 2021x through No Magic Release 2022x **Description** A stored Cross-site Scripting (XSS) issue allows an attacker to execute arbitrary script code. **Recommendations** For versions No Magic Release 2021x through No Magic Release 2022x, update to a version that is not affected by this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.