Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lamouchi

#28123of 53,630
9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-37185
4.0
2025-09-11
Undefined · Undefined · CVE-2025-10253
A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation of the argument Filedata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
PT-2025-20638
5.0
2025-05-10
Inetum · Inetum Iodas · CVE-2025-4512
**Name of the Vulnerable Software and Affected Versions** Inetum IODAS versions 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7 **Description** A problematic issue has been discovered, affecting an unknown function of the file /astre/iodasweb/app.jsp. The manipulation of the `action` argument leads to cross-site scripting. This issue can be exploited remotely. The exploit has been publicly disclosed. **Recommendations** For Inetum IODAS versions 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7, as a temporary workaround, consider restricting access to the `/astre/iodasweb/app.jsp` file to minimize the risk of exploitation. Avoid using the `action` argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.