Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pr3D4Dor

#21358of 53,630
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-26533
6.1
2024-06-26
Mapos · Mapos · CVE-2024-35545
**Name of the Vulnerable Software and Affected Versions** MAP-OS versions 4.45.0 and earlier **Description** The issue is related to a cross-site scripting (XSS) vulnerability. Cross-site scripting is a type of security vulnerability that occurs when an attacker is able to inject malicious scripts into a website, allowing them to steal user data or take control of the user's session. **Recommendations** For MAP-OS versions 4.45.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-27168
5.4
2024-06-25
Mapos · Mapos · CVE-2024-36819
**Name of the Vulnerable Software and Affected Versions** MAP-OS versions 4.45.0 and earlier **Description** The issue allows malicious users to insert a malicious payload into the `Client Name` input, resulting in unauthorized script execution on the administrator and employee dashboards when a service order from this client is created. **Recommendations** For MAP-OS versions 4.45.0 and earlier, consider restricting the input for the `Client Name` field to prevent malicious payload insertion until a fix is available. As a temporary workaround, limit access to the administrator and employee dashboards to minimize the risk of exploitation.