Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zekvan Arslan

Researcher fromInvicti
#21375of 53,633
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-10498
6.1
2020-03-19
Ilch · Ilchcms · CVE-2019-20522
**Name of the Vulnerable Software and Affected Versions** ilchCMS version 2.1.23 **Description** The issue allows for XSS via the `Link` parameter in the "index.php/partner/index" endpoint. **Recommendations** For ilchCMS version 2.1.23, avoid using the `Link` parameter in the "index.php/partner/index" endpoint until the issue is resolved.
PT-2019-19269
5.4
2019-02-19
Collabtive · Collabtive · CVE-2019-8935
**Name of the Vulnerable Software and Affected Versions** Collabtive version 3.1 **Description** The issue allows for XSS via the `manageuser.php?action=profile` API endpoint, specifically through the `id` parameter. **Recommendations** For Collabtive version 3.1, avoid using the `id` parameter in the `manageuser.php?action=profile` API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.