Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sabine Degen

Researcher fromSilverstripe
#21084of 53,635
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-10137
5.9
2020-07-15
Silverstripe · Silverstripe Cms · CVE-2019-19326
**Name of the Vulnerable Software and Affected Versions** Silverstripe CMS versions prior to 4.5 Silverstripe versions prior to 4.5 **Description** The issue allows for web cache poisoning through the modification of the `X-Original-Url` and `X-HTTP-Method-Override` headers. This can lead to responses with malicious HTTP headers being returned to other consumers of the cached response. **Recommendations** For Silverstripe CMS versions prior to 4.5, consider disabling HTTP Cache Headers on responses served by the framework's HTTP layer as a temporary workaround until a patch is available. Restrict access to the HTTPRequestBuilder to minimize the risk of exploitation.
PT-2018-18575
5.9
2018-11-14
Microsoft · Lync · CVE-2018-8546
**Name of the Vulnerable Software and Affected Versions** Skype for Business (affected versions not specified) Office 365 ProPlus (affected versions not specified) Microsoft Office (affected versions not specified) Microsoft Lync (affected versions not specified) **Description** A denial of service issue exists. This issue affects various Microsoft products. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.