Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Taynes-Llllztop

#26652of 53,633
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-36416
4.8
2024-12-27
Unknown · Dcat-Admin · CVE-2024-54774
**Name of the Vulnerable Software and Affected Versions** Dcat Admin version 2.2.0-beta **Description** The issue is a cross-site scripting (XSS) vulnerability. It affects the /admin/articles/create endpoint. **Recommendations** For Dcat Admin version 2.2.0-beta, consider disabling access to the /admin/articles/create endpoint until a patch is available. Avoid using this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-36417
4.8
2024-12-27
Unknown · Dcat-Admin · CVE-2024-54775
**Name of the Vulnerable Software and Affected Versions** Dcat-Admin versions 2.2.0-beta through 2.2.2-beta **Description** The issue is a Cross-Site Scripting (XSS) vulnerability. It can be exploited via the "/admin/auth/menu" and "/admin/auth/extensions" API endpoints. **Recommendations** For versions 2.2.0-beta through 2.2.2-beta, as a temporary workaround, consider restricting access to the "/admin/auth/menu" and "/admin/auth/extensions" API endpoints until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.