Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zftishack

#18929of 53,624
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-22413
5.4
2023-04-18
Unknown · Dreamer Cms · CVE-2023-29774
**Name of the Vulnerable Software and Affected Versions** Dreamer CMS version 3.0.1 **Description** The issue is related to stored Cross Site Scripting (XSS), which allows attackers to inject malicious scripts into content. This can lead to the execution of unauthorized code on the client-side. **Recommendations** For Dreamer CMS version 3.0.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-22438
8.8
2022-08-03
Jfinalcms · Jfinalcms · CVE-2022-34928
**Name of the Vulnerable Software and Affected Versions** JFinal CMS version 5.1.0 **Description** A SQL injection issue was discovered in JFinal CMS via the `/system/user` API endpoint. This allows for potential exploitation. **Recommendations** For JFinal CMS version 5.1.0, consider restricting access to the `/system/user` API endpoint until a patch is available. As a temporary workaround, avoid using sensitive queries in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.