Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shellsniper

#18276of 53,608
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2018-11763
6.1
2018-07-05
Imperavi · Angular Redactor · CVE-2018-13339
**Name of the Vulnerable Software and Affected Versions** Angular Redactor version 1.1.6 **Description** The issue allows for stored XSS attacks when HTML content mode is used in Imperavi Redactor 3. This can be demonstrated through the use of an `onerror` attribute of an `IMG` element. **Recommendations** For Angular Redactor version 1.1.6, update to a version that fixes this issue, as using the HTML content mode currently poses a risk of stored XSS attacks.
PT-2018-11765
8.8
2018-07-05
Gleez · Gleez Cms · CVE-2018-13340
**Name of the Vulnerable Software and Affected Versions** Gleez CMS version 1.2.0 **Description** The issue allows for CSRF, as demonstrated by a "page/add" request. **Recommendations** For Gleez CMS version 1.2.0, consider implementing proper CSRF protection mechanisms to prevent exploitation.