πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2020-13769 β€Ό

LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27626 β€Ό

JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27423 β€Ό

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27622 β€Ό

In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26129 β€Ό

In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25013 β€Ό

JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27625 β€Ό

In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27459 β€Ό

Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13773 β€Ό

Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and /LDMS/query_browsecomp.aspx.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24366 β€Ό

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27623 β€Ό

JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25952 β€Ό

SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25210 β€Ό

In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27191 β€Ό

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27628 β€Ό

In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.

πŸ“– Read

via "National Vulnerability Database".
⚠ Naked Security Live – Don’t get hoaxed (pass it on)! ⚠

Here's the latest Naked Security Live video - enjoy (and please share with your friends)!

πŸ“– Read

via "Naked Security".
❌ Hacked Security Software Used in Novel South Korean Supply-Chain Attack ❌

Lazarus Group is believed to be behind a spate of attacks that leverage stolen digital certificates tied to browser software that secures communication with government and financial websites in South Korea.

πŸ“– Read

via "Threat Post".
πŸ•΄ Zoom Debuts New Tools to Fight Meeting Disruptions πŸ•΄

Two new capabilities in version 5.4.3 let hosts and co-hosts pause Zoom meetings to remove and report disruptive attendees.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-27988 β€Ό

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4665 β€Ό

IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 186280.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27990 β€Ό

Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).

πŸ“– Read

via "National Vulnerability Database".