Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Le0Nsec

#21418of 53,624
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-17760
5.3
2022-03-12
Onenav · Onenav · CVE-2022-26276
**Name of the Vulnerable Software and Affected Versions** OneNav version 0.9.14 **Description** An issue in the `index.php` file allows attackers to perform directory traversal. **Recommendations** For OneNav version 0.9.14, update to a version that fixes the issue in `index.php` to prevent directory traversal attacks.
PT-2022-17924
6.1
2022-03-12
Alist · Alist · CVE-2022-26533
**Name of the Vulnerable Software and Affected Versions** Alist versions 2.0.10 through 2.1.0 **Description** The issue is a cross-site scripting (XSS) vulnerability. It occurs via the "/i/:data/ipa.plist" API endpoint. This vulnerability was fixed in version 2.1.1. **Recommendations** For versions 2.0.10 through 2.1.0, update to version 2.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the "/i/:data/ipa.plist" API endpoint until the update is applied.