Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xjzzzxxo

#13596of 53,635
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2024-29378
9.8
2024-08-29
Organizr · Organizr · CVE-2024-41370
**Name of the Vulnerable Software and Affected Versions** Organizr version 1.90 **Description** The issue is a SQL injection problem. It occurs via the `chat/setlike.php` file. **Recommendations** For Organizr version 1.90, consider restricting access to the `chat/setlike.php` file until a patch is available. As a temporary workaround, avoid using parameters that could lead to SQL injection in the affected endpoint. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-29380
9.8
2024-08-29
Organizr · Organizr · CVE-2024-41372
**Name of the Vulnerable Software and Affected Versions** Organizr version 1.90 **Description** A SQL injection issue was found in Organizr via the `chat/settyping.php` endpoint. This allows for potential exploitation. **Recommendations** For Organizr version 1.90, consider restricting access to the `chat/settyping.php` endpoint until a patch is available. Avoid using user-supplied input in SQL queries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.