Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-2094PUBLISHED: 2023-02-08The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting
CVE-2022-43761PUBLISHED: 2023-02-08Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.
CVE-2023-0740PUBLISHED: 2023-02-08Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0741PUBLISHED: 2023-02-08Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0742PUBLISHED: 2023-02-08Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
User Rank: Strategist
11/21/2013 | 6:38:26 PM
The other three researchers concurred, rather emphatically, if you watched the hearing. Perhaps it would be prudent to wait until the site is fixed and the researchers can release the information on the other issues they found before dismissing their findings. Given the number of other technical shortcomings the site has had, the fact that it was put into production in spite of warnings as far back as last March that it wouldn't be ready, the revelation that it was never properly tested and the statement that there are over 500 million lines of code involved, I don't think it would be a surprise if it was found as insecure or more so than most other federal government web sites.