Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lars Neumann

Researcher fromusd AG
#18681of 53,624
14.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-17727
8.3
2021-03-05
Deutsche Post · Deutsche Post Mailoptimizer · CVE-2021-28042
Name of the Vulnerable Software and Affected Versions: Deutsche Post Mailoptimizer versions prior to 2020-11-09 Description: The issue allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component, potentially leading to remote code execution. Recommendations: For versions prior to 2020-11-09, update to a version released after 2020-11-09 to resolve the issue. As a temporary workaround, consider restricting access to the Upload feature and the MO Connect component to minimize the risk of exploitation.
PT-2020-16881
6.1
2020-10-28
Neopost · Neopost Mail Accounting Software Pro · CVE-2020-27974
**Name of the Vulnerable Software and Affected Versions** NeoPost Mail Accounting Software Pro version 5.0.6 **Description** The issue allows for XSS in the php/Commun/FUS SCM BlockStart.php endpoint, specifically through the `code` parameter. **Recommendations** For NeoPost Mail Accounting Software Pro version 5.0.6, avoid using the `code` parameter in the php/Commun/FUS SCM BlockStart.php endpoint until the issue is resolved.