Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nico Trionfetti

#20627of 53,633
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2023-22369
6.1
2023-06-09
Vade Secure · Vade Secure Gateway · CVE-2023-29713
**Name of the Vulnerable Software and Affected Versions** Vade Secure Gateway (affected versions not specified) **Description** A Cross Site Scripting issue allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the `/css/` directory. This enables the attacker to inject malicious scripts into the application, potentially leading to unauthorized actions. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-22370
6.1
2023-06-09
Vade Secure · Vade Secure Gateway · CVE-2023-29714
**Name of the Vulnerable Software and Affected Versions** Vade Secure Gateway (affected versions not specified) **Description** A Cross Site Scripting issue allows a remote attacker to execute arbitrary code via the `username`, `password`, and `language` cookies parameter. This enables the attacker to perform unauthorized actions on the affected system. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.