CVE-2024-55227 |
Description: A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
References
https://nvd.nist.gov/vuln/detail/CVE-2024-55227
https://github.com/Dolibarr/dolibarr/commit/56710ce9b79a97df093f586c90bdaf6cce6a5808
https://github.com/Dolibarr/dolibarr/commit/9aa24d9d9aeab36358c725dae3fe20c9631082e7
https://github.com/Dolibarr/dolibarr/commit/c0250e4c9106b5c889e512a4771f0205d4f99b99
https://gist.github.com/Dqtdqt/9762466cd6ec541ea265ba33b09489ff
https://github.com/Dolibarr/dolibarr/security/policy
https://github.com/advisories/GHSA-2v3r-gvq5-qqgh
EPSS Score: 0.12%
January 27th, 2025 (5 months ago)
|
CVE-2024-55228 |
Description: A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
References
https://nvd.nist.gov/vuln/detail/CVE-2024-55228
https://github.com/Dolibarr/dolibarr/commit/56710ce9b79a97df093f586c90bdaf6cce6a5808
https://github.com/Dolibarr/dolibarr/commit/9aa24d9d9aeab36358c725dae3fe20c9631082e7
https://github.com/Dolibarr/dolibarr/commit/c0250e4c9106b5c889e512a4771f0205d4f99b99
https://gist.github.com/Dqtdqt/a942bbce9a5fc851dce366902411c768
https://github.com/Dolibarr/dolibarr/security/policy
https://github.com/advisories/GHSA-x2j8-vjg7-386r
EPSS Score: 0.12%
January 27th, 2025 (5 months ago)
|
![]() |
Description: Microsoft has confirmed that the January 2025 Windows security updates are breaking audio playback on some systems with external DACs (digital-to-analog converters). [...]
January 27th, 2025 (5 months ago)
|
![]() |
Description: Hackers behind the breach of “nearly all” of AT&T customers’ metadata searched for records associated with members of the Trump family, Kamala Harris, and Marco Rubio’s wife.
January 27th, 2025 (5 months ago)
|
![]() |
Description: ONE Thousand and ONE Defaced Six Different Indian Websites
January 27th, 2025 (5 months ago)
|
![]() |
Description: Apple has released security updates to fix this year's first zero-day vulnerability, tagged as actively exploited in attacks targeting iPhone users. [...]
January 27th, 2025 (5 months ago)
|
![]() |
Description: The European Union sanctioned three hackers, part of Unit 29155 of Russia's military intelligence service (GRU), for their involvement in cyberattacks targeting Estonia's government agencies in 2020. [...]
January 27th, 2025 (5 months ago)
|
![]() |
Description: Windows 11 taskbar is testing a new feature that helps you understand the current power state of your laptop's battery, including showing the battery percentage directly on the taskbar. [...]
January 27th, 2025 (5 months ago)
|
![]() |
Description: In a slate of several bills restricting reproductive rights and divorce, Oklahoma senator Dusty Deevers suggests anyone making anything even vaguely pornographic should go to jail.
January 27th, 2025 (5 months ago)
|
![]() |
Description: The Phemex crypto exchange suffered a massive security breach on Thursday where threat actors stole over $85 million worth of cryptocurrency. [...]
January 27th, 2025 (5 months ago)
|