Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Riteshgupta1993

#21853of 53,633
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-13705
5.4
2018-09-12
Feindura · Feindura · CVE-2018-16728
**Name of the Vulnerable Software and Affected Versions** feindura version 2.0.7 **Description** The issue allows for XSS via the `tags` field of a new page created at "index.php?category=0&page=new". **Recommendations** For feindura version 2.0.7, consider restricting access to the `tags` field in the new page creation process at "index.php?category=0&page=new" until a patch is available.
PT-2018-13706
5.4
2018-09-12
Pluck · Pluck · CVE-2018-16729
**Name of the Vulnerable Software and Affected Versions** Pluck version 4.7.7 **Description** The issue allows for XSS (Cross-Site Scripting) attacks via an SVG file containing Javascript in a SCRIPT element. This file can be uploaded through the 'pages->manage' section under the 'admin.php?action=files' endpoint. **Recommendations** For Pluck version 4.7.7, consider restricting access to the file upload functionality under 'admin.php?action=files' to minimize the risk of exploitation. As a temporary workaround, avoid using the file upload feature in the 'pages->manage' section until a patch is available.