Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ravinder Verma

#49977of 53,635
4.8Total CVSS
Vulnerabilities · 1
PT-2022-11469
4.8
2022-09-16
Unknown · Mysql Server · CVE-2021-41731
**Name of the Vulnerable Software and Affected Versions** Sourcecodester News247 News Magazine (CMS) versions 5.6 and higher of PHP, and versions 5.7 and higher of MySQL **Description** A Cross Site Scripting (XSS) issue exists via the blog category name field. This allows for potential malicious script execution. **Recommendations** For PHP versions 5.6 and higher, and MySQL versions 5.7 and higher, consider validating and sanitizing user input in the blog category name field to prevent XSS attacks. As a temporary workaround, consider restricting access to the blog category name field until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.