Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Markus Schader

Researcher fromusd AG
#16845of 53,635
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2021-12495
9.8
2021-03-19
Unknown · It-Recht Kanzlei · CVE-2020-6577
Name of the Vulnerable Software and Affected Versions: Zen Cart version 1.5.6c Description: The issue concerns a SQL Injection vulnerability in the IT-Recht Kanzlei plugin. Specifically, the `itrk-api.php` endpoint is affected, allowing SQL Injection through the `rechtstext language` parameter. Recommendations: For Zen Cart version 1.5.6c, consider disabling the IT-Recht Kanzlei plugin until a patch is available to prevent exploitation of the SQL Injection vulnerability in the `itrk-api.php` endpoint. Restrict access to the `itrk-api.php` endpoint to minimize the risk of exploitation. Avoid using the `rechtstext language` parameter in the affected endpoint until the issue is resolved.
PT-2021-12496
6.1
2021-03-19
Zen Cart · Zen Cart · CVE-2020-6578
Name of the Vulnerable Software and Affected Versions: Zen Cart version 1.5.6d Description: The issue allows reflected XSS via the `main page` parameter to files such as `includes/templates/template default/common/tpl main page.php` or `includes/templates/responsive classic/common/tpl main page.php`. Recommendations: For Zen Cart version 1.5.6d, as a temporary workaround, consider restricting access to the `main page` parameter in the affected files until a patch is available.