Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Satuer

Researcher fromABT Labs
#14435of 53,624
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2019-13497
8.8
2019-07-18
Flatcore · Flatcore · CVE-2019-13961
**Name of the Vulnerable Software and Affected Versions** flatCore versions prior to 1.5 **Description** A CSRF issue was discovered, allowing the upload of arbitrary .php files via the "acp/core/files.upload-script.php" endpoint. **Recommendations** For versions prior to 1.5, update to version 1.5 or later to resolve the issue.
PT-2019-13121
9.8
2019-06-30
Csz · Csz Cms · CVE-2019-13086
**Name of the Vulnerable Software and Affected Versions** CSZ CMS version 1.2.2 **Description** The issue allows for SQL injection by sending a crafted HTTP User-Agent header and omitting the `csrf csz` parameter in the `core/MY Security.php` file. **Recommendations** For CSZ CMS version 1.2.2, as a temporary workaround, consider restricting access to the `member/login/check` endpoint until a patch is available. Avoid using the `csrf csz` parameter omission in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.