Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rodrigo Favarini

Researcher fromMITM Labs
#20551of 53,630
12.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-24212
6.3
2024-06-27
Unknown · Designa Abacus · CVE-2024-31802
**Name of the Vulnerable Software and Affected Versions** DESIGNA ABACUS versions prior to v.19 **Description** The issue allows an attacker to bypass the payment process via a crafted QR code. **Recommendations** For versions prior to v.19, update to a version that includes a fix for this issue to prevent bypassing the payment process. As a temporary workaround, consider restricting the use of QR code payments until a patch is available.
PT-2020-16824
6.1
2020-10-29
Wso2 · Wso2 Api Manager · CVE-2020-27885
**Name of the Vulnerable Software and Affected Versions** WSO2 API Manager version 3.1.0 **Description** A Cross-Site Scripting (XSS) issue allows an attacker to hijack a logged-in user's session by stealing cookies. This enables a malicious hacker to change the logged-in user's password and invalidate the session of the victim while maintaining access. **Recommendations** For WSO2 API Manager version 3.1.0, update to a version that includes a fix for this issue to prevent session hijacking and unauthorized password changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.