Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Slackero

#16905of 53,624
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2023-12405
9.8
2023-01-07
Phpcms · Phpcms · CVE-2021-4301
**Name of the Vulnerable Software and Affected Versions** slackero phpwcms versions 1.9.26 and earlier **Description** A critical issue was found in the software, affecting some unknown functionality. The manipulation of the argument `$phpwcms['db prepend']` leads to SQL injection. The attack can be launched remotely. **Recommendations** For versions 1.9.26 and earlier, upgrade to version 1.9.27 to address this issue. As a temporary workaround, consider restricting the use of the `$phpwcms['db prepend']` argument until the upgrade is applied.
PT-2023-12406
6.1
2023-01-04
Slackero · Phpcms · CVE-2021-4302
**Name of the Vulnerable Software and Affected Versions** slackero phpwcms versions up to 1.9.26 **Description** A vulnerability was found in the SVG File Handler component of slackero phpwcms, which can be exploited to lead to cross site scripting. The manipulation can be initiated remotely. **Recommendations** For versions up to 1.9.26, upgrade to version 1.9.27 to address this issue.