Category Archives: Advisories

WordPress v5.9 – Reflected Cross Site Scripting Web Vulnerability

Read Time:16 Second

Posted by info () vulnerability-lab com on Feb 18

Document Title:
===============
Wordpress v5.9 – Reflected Cross Site Scripting Web Vulnerability

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2316

Release Date:
=============
2022-02-09

Vulnerability Laboratory ID (VL-ID):
====================================
2316

Common Vulnerability Scoring System:
====================================
4.2

Vulnerability Class:
====================
Cross…

Read More

Car Portal Template – (Search) Persistent Web Vulnerability

Read Time:15 Second

Posted by info () vulnerability-lab com on Feb 18

Document Title:
===============
Car Portal Template – (Search) Persistent Web Vulnerability

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2299

Release Date:
=============
2022-02-08

Vulnerability Laboratory ID (VL-ID):
====================================
2299

Common Vulnerability Scoring System:
====================================
5.6

Vulnerability Class:
====================
Cross Site…

Read More

Multiple Vulnerabilities in Adobe Commerce and Magento Could Allow for Remote Code Execution

Read Time:36 Second

Multiple vulnerabilities have been discovered in Adobe Commerce and Magento Open Source, the most severe of which could allow for remote code execution.

Adobe Commerce is a leading provider of cloud commerce innovation to merchants and brands across B2C and B2B industries.
Magento is a web-based e-commerce application written in PHP.
Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

Read More

CVE-2020-8107

Read Time:18 Second

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.

Read More