Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kazi Sabbir

#21379of 57,349
13.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-94376
7.1
2026-09-17
Rosariosis · Rosariosis · CVE-2026-93014
**Name of the Vulnerable Software and Affected Versions** RosarioSIS versions prior to 12.9 **Description** Authenticated users can delete allow-listed files through a path traversal flaw in the Users and Students modules. By using parent-directory sequences in the `filename` request parameter, an attacker can escape upload directories to unlink CSS, XML, JSON resources, and documents belonging to other users across the installation. Path traversal is a technique used to access files and directories that are stored outside the web root folder. **Recommendations** Update to version 12.9 or later. Restrict the use of the `filename` parameter in the Users and Students modules until the update is applied.
PT-2026-93257
6.3
2026-09-16
Espocrm · Espocrm · CVE-2026-92298
**Name of the Vulnerable Software and Affected Versions** EspoCRM versions prior to 10.0.9 **Description** The software uses the PHP `rand()` function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs. Because `rand()` is not a cryptographically secure generator, remote unauthenticated attackers can guess these approximately 31-bit tokens. This allows attackers to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details. **Recommendations** Update EspoCRM to version 10.0.9 or later.