Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nam3Lumo

#18228of 53,633
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-15959
8.8
2022-02-19
Wikidocs · Wikidocs · CVE-2022-23375
**Name of the Vulnerable Software and Affected Versions** WikiDocs version 0.1.18 **Description** The issue allows for authenticated remote code execution. An attacker can exploit this by uploading a malicious file using the `image upload form` through the "index.php" endpoint. The `image upload form` is vulnerable to malicious file uploads, which can be used to execute arbitrary code. **Recommendations** For WikiDocs version 0.1.18, consider disabling the image upload functionality through the "index.php" endpoint until a patch is available to prevent exploitation. Restrict access to the image upload form to minimize the risk of remote code execution.
PT-2022-15960
6.1
2022-02-19
Wikidocs · Wikidocs · CVE-2022-23376
**Name of the Vulnerable Software and Affected Versions** WikiDocs version 0.1.18 **Description** The issue concerns multiple reflected XSS vulnerabilities found on different pages. **Recommendations** For WikiDocs version 0.1.18, update to a version that addresses the reflected XSS vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.