Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tr0Ee

#16807of 53,624
16Total CVSS
Vulnerabilities · 2
High
2
PT-2022-26317
8.8
2022-10-11
Unknown · Wedding Planner · CVE-2022-42229
**Name of the Vulnerable Software and Affected Versions** Wedding Planner version 1.0 **Description** The issue allows for arbitrary code execution via the "package edit.php" endpoint. **Recommendations** For version 1.0, update to a version that fixes this issue, if available, or consider disabling access to the "package edit.php" endpoint as a temporary workaround to minimize the risk of exploitation.
PT-2022-26319
7.2
2022-10-11
Unknown · Simple Cold Storage Management System · CVE-2022-42230
**Name of the Vulnerable Software and Affected Versions** Simple Cold Storage Management System version 1.0 **Description** The issue allows for SQL Injection via the "/csms/admin/?page=user/manage user&id=" API endpoint, specifically targeting the `id` variable. This could potentially lead to unauthorized access or manipulation of data. **Recommendations** For Simple Cold Storage Management System version 1.0, consider disabling the `/csms/admin/?page=user/manage user` endpoint until a patch is available, or restrict access to it to minimize the risk of exploitation. Avoid using the `id` variable in the affected API endpoint until the issue is resolved.