Novel-Plus ଯେପର୍ଯ୍ୟନ୍ତ 4.2.0 HTTP POST Request /user/updateUserInfo nickName କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ
Rakkoon nageenyaa kan ସମସ୍ୟାଜନକ jedhamuun beekamu Novel-Plus ଯେପର୍ଯ୍ୟନ୍ତ 4.2.0 keessatti argameera. Kan miidhamte is hojii hin beekamne faayilii /user/updateUserInfo keessa kutaa HTTP POST Request Handler keessa. Hojii jijjiirraa irratti gaggeeffame nickName gara କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ geessa. CWE fayyadamuun rakkoo ibsuun gara CWE-79 geessa. Dadhabbii kana yeroo 12/28/2023 maxxanfameera akka c62da9bb3a9b3603014d0edb436146512631100d. Odeeffannoon kun buufachuuf github.com irratti qoodameera. Dogoggorri kun akka CVE-2023-7166tti beekama. Yaaliin weeraraa fageenya irraa jalqabamuu ni danda'a. Faayidaaleen teeknikaa ni jiru. Waliigalatti, meeshaa balaa kana fayyadamuuf jiru. Qorannoo miidhaa (exploit) uummataaf ifoomameera fi fayyadamamuu danda'a. Amma, gatii ammee exploit might be approx. USD $0-$5k ta'uu danda'a. Akka ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee ibsameera. Carraa exploit kana github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatii daldalaa dhoksaa tilmaamame $0-$5k ta'ee ture. Beekamtii paachii kanaa c62da9bb3a9b3603014d0edb436146512631100d dha. Sirreeffamni rakkoo github.com irratti buufachuuf qophaa’eera. Paachii itti fayyadamuun rakkoo kana furuuf ni gorfama. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.
3 ଆଡାପ୍ଟେସନ୍ · 75 ପଏଣ୍ଟ