Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

K1Ns0O

#18286of 53,630
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2018-13859
8.8
2018-09-14
Maelo · Cms Maelostore · CVE-2018-17045
**Name of the Vulnerable Software and Affected Versions** CMS MaeloStore version 1.5.0 **Description** A CSRF issue allows changing the administrator password via the "admin/modul/users/aksi users.php?act=update" API endpoint. **Recommendations** For CMS MaeloStore version 1.5.0, as a temporary workaround, consider restricting access to the "admin/modul/users/aksi users.php?act=update" endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2018-13111
6.1
2018-08-21
Victor · Victor Cms · CVE-2018-15603
**Name of the Vulnerable Software and Affected Versions** Victor CMS versions prior to 2018-05-10 **Description** An issue was discovered that allows for XSS via the `Author` field of the "Leave a Comment" screen. **Recommendations** For versions prior to 2018-05-10, update to a version released after 2018-05-10 to resolve the issue.