Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jacinta

#23261of 57,309
11.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-97688
4.0
2026-09-24
Unknown · Base-Admin · CVE-2026-96810
**Name of the Vulnerable Software and Affected Versions** huanzi-qch base-admin versions up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1 **Description** A remote cross site scripting issue exists in the Add User Handler component. The problem occurs within the `Save()` function located in the `base-admin-mastersrcmainjavacnhuanziqchbaseadmincommoncontrollerCommonController.java` file. An attacker can trigger this by manipulating the `Username` variable. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the `Save()` function or sanitize the `Username` input to minimize the risk of exploitation.
PT-2026-91220
7.5
2026-09-14
Unknown · Soarkey Studentmanagement · CVE-2026-90787
**Name of the Vulnerable Software and Affected Versions** Soarkey StudentManagement versions up to e08f7f1d5015af407aa4cca0ada3dea189b4937e **Description** Improper privilege management exists within the Registration Workflow component. A remote attacker can manipulate the argument level in the `RegisterServlet.doPost()` function located in the `code/WebContent/register.html` file to gain unauthorized privileges. **Recommendations** As a temporary workaround, restrict access to the `RegisterServlet.doPost()` function until a fix is provided.