Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Patrick Schlüter

Researcher fromSySS GmbH
#18755of 53,633
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-14539
5.4
2023-04-17
Unknown · Touchdown Timesheet Tracking Component For Jira · CVE-2022-44726
**Name of the Vulnerable Software and Affected Versions** TouchDown Timesheet tracking component for Jira version 4.1.4 **Description** The issue allows for XSS in the calendar view. **Recommendations** For version 4.1.4, update to a version that fixes the XSS issue in the calendar view, as the current version allows for XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-27285
8.9
2022-11-04
Stiltsoft · Stiltsoft Handy Macros For Confluence Server/Data Center · CVE-2022-44724
**Name of the Vulnerable Software and Affected Versions** Stiltsoft Handy Macros for Confluence Server/Data Center versions 3.x through 3.5.4 **Description** The issue allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Handy Tip macro. This can be exploited by attackers to inject malicious code. **Recommendations** For versions 3.x through 3.5.4, update to version 3.5.5 or later to resolve the issue. As a temporary workaround, consider disabling the Handy Tip macro until a patch is available. Restrict access to the macro to minimize the risk of exploitation.