Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matt Schmidt

Researcher fromTriaxiom Security
#20596of 53,633
12.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-15929
4.8
2022-02-10
Xmpie · Xmpie Ustore · CVE-2022-23321
**Name of the Vulnerable Software and Affected Versions** XMPie UStore version 12.3.7244.0 **Description** A persistent cross-site scripting (XSS) issue exists in the administrative panel when editing users, specifically affecting two input fields. **Recommendations** For version 12.3.7244.0, consider temporarily disabling the editing functionality for users in the administrative panel until a patch is available. Restrict access to the administrative panel to minimize the risk of exploitation.
PT-2022-15928
7.5
2022-02-07
Xmpie · Xmpie Ustore · CVE-2022-23320
**Name of the Vulnerable Software and Affected Versions** XMPie uStore version 12.3.7244.0 **Description** The issue allows administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database. **Recommendations** For XMPie uStore version 12.3.7244.0, change the default administrative credentials to prevent unauthorized access and consider restricting the ability to generate reports based on raw SQL queries to minimize the risk of sensitive information exfiltration.