Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Matthew Hier

Researcher fromTriaxiom Security
#22003of 56,333
12.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-15929
4.8
2022-02-10
Xmpie · Xmpie Ustore · CVE-2022-23321
**Name of the Vulnerable Software and Affected Versions** XMPie UStore version 12.3.7244.0 **Description** A persistent cross-site scripting (XSS) issue exists in the administrative panel when editing users, specifically affecting two input fields. **Recommendations** For version 12.3.7244.0, consider temporarily disabling the editing functionality for users in the administrative panel until a patch is available. Restrict access to the administrative panel to minimize the risk of exploitation.
PT-2022-15928
7.5
2022-02-07
Xmpie · Xmpie Ustore · CVE-2022-23320
**Name of the Vulnerable Software and Affected Versions** XMPie uStore version 12.3.7244.0 **Description** The issue allows administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database. **Recommendations** For XMPie uStore version 12.3.7244.0, change the default administrative credentials to prevent unauthorized access and consider restricting the ability to generate reports based on raw SQL queries to minimize the risk of sensitive information exfiltration.