Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vipinxsec

#21935of 53,622
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2019-15858
5.4
2019-12-02
Alfresco · Alfresco Enterprise · CVE-2019-19496
**Name of the Vulnerable Software and Affected Versions** Alfresco Enterprise versions prior to 5.2.5 **Description** The issue allows for stored XSS via an uploaded HTML document. This means an attacker can upload a malicious HTML file to the system, which can then execute scripts on the user's browser, potentially leading to unauthorized actions or data theft. **Recommendations** For versions prior to 5.2.5, update to version 5.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the upload of HTML documents to minimize the risk of exploitation.
PT-2018-18604
5.4
2018-03-19
Wampserver · Wampserver · CVE-2018-8732
**Name of the Vulnerable Software and Affected Versions** WampServer version 3.1.1 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `virtual del` parameter. This can lead to the execution of malicious scripts on the client-side. **Recommendations** For WampServer version 3.1.1, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.