Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Retnullyu

#20629of 53,624
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-25364
6.1
2022-09-14
Gocron · Gocron · CVE-2022-40365
**Name of the Vulnerable Software and Affected Versions** gocron versions through 1.5.3 **Description** A cross-site scripting (XSS) issue allows attackers to execute arbitrary code via the `hostname` in the `scope.row` object, specifically in the web/vue/src/pages/taskLog/list.vue file. **Recommendations** For versions through 1.5.3, update to a version that contains a fix for this issue to prevent arbitrary code execution.
PT-2022-15972
6.1
2022-02-14
Pybbs · Pybbs · CVE-2022-23391
**Name of the Vulnerable Software and Affected Versions** Pybbs version 6.0 **Description** A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Search box. **Recommendations** For Pybbs version 6.0, consider restricting access to the Search box until a patch is available. As a temporary workaround, avoid using the Search box with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.