Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nilesh

#37976of 53,632
7.3Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2024-39541
1.9
2024-09-27
Unknown · Relaxedjs Relaxed · CVE-2024-9283
**Name of the Vulnerable Software and Affected Versions** RelaxedJS ReLaXed versions up to 0.2.2 **Description** A problematic issue has been found in the Pug to PDF Converter component, which can lead to cross-site scripting. The manipulation requires a local approach to execute an attack. The issue has been publicly disclosed. **Recommendations** For RelaxedJS ReLaXed versions up to 0.2.2, consider disabling the Pug to PDF Converter component until a patch is available to prevent potential cross-site scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-39409
5.4
2024-09-21
Stirling Tools · Stirling-Pdf · CVE-2024-9075
**Name of the Vulnerable Software and Affected Versions** Stirling-Tools Stirling-PDF versions up to 0.28.3 **Description** A vulnerability was found in the Markdown-to-PDF component of Stirling-Tools Stirling-PDF, leading to cross-site scripting. The attack can be initiated remotely, with a rather high complexity and difficult exploitation. **Recommendations** For Stirling-Tools Stirling-PDF versions up to 0.28.3, upgrade to version 0.29.0 to address this issue. As a temporary workaround, consider disabling the Markdown-to-PDF functionality until the upgrade is applied.