Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Manich Koomsusi

#15327of 53,639
17.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2019-13810
7.8
2019-10-14
Ubisoft · Uplay · CVE-2019-14737
**Name of the Vulnerable Software and Affected Versions** Uplay version 92.0.0.6280 **Description** The issue is related to insecure permissions in the software. **Recommendations** For version 92.0.0.6280, update to a newer version that addresses the insecure permissions issue.
PT-2017-19206
9.8
2017-09-07
WordPress · Watupro · CVE-2017-9834
**Name of the Vulnerable Software and Affected Versions** WatuPRO plugin versions prior to 5.5.3.7 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `watupro questions` parameter in a `watupro submit` action to the "/wp-admin/admin-ajax.php" API endpoint. **Recommendations** For versions prior to 5.5.3.7, update to version 5.5.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/wp-admin/admin-ajax.php" API endpoint to minimize the risk of exploitation. Avoid using the `watupro questions` parameter in the affected API endpoint until the issue is resolved.