Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nhienit2010

#18218of 53,635
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-22411
8.8
2023-11-27
Unknown · Sentrifugo · CVE-2023-29770
**Name of the Vulnerable Software and Affected Versions** Sentrifugo version 3.5 **Description** The issue allows an authenticated attacker to upload any file without extension filtering through the AssetsController::uploadsaveAction function. **Recommendations** For Sentrifugo version 3.5, consider restricting access to the AssetsController::uploadsaveAction function until a patch is available, and implement proper file extension filtering to minimize the risk of exploitation.
PT-2022-19093
6.1
2022-04-25
Hoosk · Hoosk · CVE-2022-28586
**Name of the Vulnerable Software and Affected Versions** Hoosk version 1.8.0 **Description** The issue allows an attacker to execute javascript code in a user's browser via the edit page with an XSS payload, bypassing filters for some special characters. **Recommendations** For Hoosk version 1.8.0, update to a version that includes a fix for this issue, as using the edit page with an XSS payload can lead to the execution of malicious javascript code in the user's browser. At the moment, there is no information about a newer version that contains a fix for this vulnerability.