Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vickey Tsai

Researcher fromAcer Cyber Security
#47028of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2023-27916
5.4
2023-11-02
Rogic · Rogic No-Code Database Builder · CVE-2023-41343
**Name of the Vulnerable Software and Affected Versions** Rogic No-Code Database Builder (affected versions not specified) **Description** The issue concerns the file uploading function in Rogic No-Code Database Builder, which has insufficient filtering for special characters. This allows a remote attacker with regular user privileges to inject JavaScript, enabling a Stored Cross-Site Scripting (XSS) attack. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.