Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yazi7O

#20316of 53,635
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-19094
5.4
2022-05-03
Unknown · Springbootmovie · CVE-2022-28588
**Name of the Vulnerable Software and Affected Versions** SpringBootMovie versions 1.2 and earlier **Description** The issue allows malicious code to be stored when adding movie names due to the lack of filtering parameters, resulting in stored XSS. **Recommendations** For SpringBootMovie versions 1.2 and earlier, consider implementing filtering parameters to prevent the storage of malicious code when adding movie names. As a temporary workaround, restrict the ability to add movie names until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-19356
7.2
2022-05-03
Unknown · Springbootmovie · CVE-2022-29001
**Name of the Vulnerable Software and Affected Versions** SpringBootMovie versions 1.2 and earlier **Description** The issue is related to an arbitrary file upload vulnerability due to the uploaded file suffix parameter not being filtered. **Recommendations** For SpringBootMovie versions 1.2 and earlier, as a temporary workaround, consider filtering the uploaded file suffix parameter to prevent arbitrary file uploads until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.