Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nelson Fernandes

Researcher fromThe Missing Link Security
#16615of 53,630
16.2Total CVSS
Vulnerabilities · 2
High
2
PT-2022-20193
8.6
2022-10-31
Red Os · Red Os · CVE-2022-3059
**Name of the Vulnerable Software and Affected Versions** No specific software or versions are mentioned. **Description** The issue allows for SQL injection, both authenticated and unauthenticated, through a vulnerable parameter. This parameter can be used to craft and inject complex SQL commands due to stacked query support. Additionally, a sleep-based inferential SQL injection technique can be employed to extract data from the database. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-24676
7.6
2022-10-31
Schoolbox Pty · Schoolbox · CVE-2022-39020
**Name of the Vulnerable Software and Affected Versions** No specific software or versions mentioned. **Description** The application is affected by multiple instances of cross-site scripting (XSS), including both stored and reflected XSS. Vulnerable features include student assessment submission, file upload, news, ePortfolio, and calendar event creation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.