Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mustgundogdu

#21298of 53,633
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-15338
5.4
2022-01-01
Dolibarr · Dolibarr · CVE-2022-22293
**Name of the Vulnerable Software and Affected Versions** Dolibarr version 7.0.2 **Description** The issue allows HTML injection, as demonstrated by the `MAIN MAX DECIMALS TOT` parameter in the "admin/limits.php" endpoint. **Recommendations** For Dolibarr version 7.0.2, consider restricting access to the "admin/limits.php" endpoint until a patch is available, and avoid using the `MAIN MAX DECIMALS TOT` parameter to minimize the risk of exploitation.
PT-2020-17158
6.1
2020-11-30
WordPress · Eventon · CVE-2020-29395
**Name of the Vulnerable Software and Affected Versions** EventON plugin versions 3.0.5 and earlier **Description** The issue allows for XSS via the search field in the addons/?q= endpoint. This is a security concern as it can be exploited to inject malicious scripts. **Recommendations** For versions 3.0.5 and earlier, as a temporary workaround, consider restricting access to the `addons/?q=` endpoint until a patch is available. Avoid using the search field in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.