Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yllxx03

#20105of 53,633
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-34374
7.5
2024-11-15
Unknown · Python Food Ordering System · CVE-2024-50647
Name of the Vulnerable Software and Affected Versions: python food ordering system version V1.0 Description: The python food ordering system has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through the "https://ip:port/api/myapp/index/user/info?id=1" API endpoint and modify the `id` value to obtain sensitive user information beyond authorization. Recommendations: For version V1.0, as a temporary workaround, consider restricting access to the "/api/myapp/index/user/info" API endpoint until a patch is available. Avoid using the `id` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-34383
5.4
2024-11-15
Emlog Pro · Emlog Pro · CVE-2024-50655
Name of the Vulnerable Software and Affected Versions: emlog pro versions 2.3.18 and earlier Description: The issue allows attackers to write malicious JavaScript code in published articles, potentially leading to Cross Site Scripting (XSS) attacks. Recommendations: For emlog pro versions 2.3.18 and earlier, update to a version later than 2.3.18 to resolve the issue.