Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24131: GitHub - zpxlz/douphp: douphp

DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.

CVE
#xss#vulnerability#git#java

XSS vulnerability exists in douphp background adding articles.

Official demo site, administrator login. https://demo.douphp.com/admin/login.php

Source download address. https://down.douphp.com/DouPHP_1.6_Release_20220121.zip

Log in to the background and add articles. image

Insert XSS code at the article name,Submit.

<script>alert(document.cookie)</script>

image

Cookie pops up in the background. image

The foreground will also trigger vulnerabilities. image

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907