Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Johnson

#18255of 53,619
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-28055
6.1
2022-12-25
Unknown · Kkfileview · CVE-2022-4740
**Name of the Vulnerable Software and Affected Versions** kkFileView (affected versions not specified) **Description** A problematic issue has been found in kkFileView, affecting the `setWatermarkAttribute` function of the file `/picturesPreview`. This issue leads to cross-site scripting and can be launched remotely. The exploit has been disclosed to the public. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-26693
8.8
2022-10-17
Unknown · Anji-Plus Aj-Report · CVE-2022-42983
**Name of the Vulnerable Software and Affected Versions** anji-plus AJ-Report version 0.9.8.6 **Description** The issue allows remote attackers to bypass login authentication by spoofing JWT Tokens. This can be exploited by attackers to gain unauthorized access to the system. **Recommendations** For anji-plus AJ-Report version 0.9.8.6, consider disabling the use of JWT Tokens for login authentication until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the `token` variable in authentication processes until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.