Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zaran Shaikh

#26562of 53,632
9.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-8035
4.3
2022-08-24
Kirby · Kirby · CVE-2018-14519
**Name of the Vulnerable Software and Affected Versions** Kirby version 2.5.12 **Description** The delete page functionality in Kirby suffers from a CSRF flaw, allowing a remote attacker to craft a malicious page and force the user to delete a page. **Recommendations** For Kirby version 2.5.12, consider disabling the delete page functionality until a patch is available to prevent exploitation of the CSRF flaw. Restrict access to the delete page feature to minimize the risk of unauthorized page deletion.
PT-2022-8036
5.4
2022-08-24
Kirby · Kirby · CVE-2018-14520
**Name of the Vulnerable Software and Affected Versions** Kirby version 2.5.12 **Description** The issue allows malicious HTTP requests to be sent, which can trick a user into adding web pages. **Recommendations** For Kirby version 2.5.12, at the moment, there is no information about a newer version that contains a fix for this issue.