🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2020-28206

An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.

📖 Read

via "National Vulnerability Database".
Spotify Wrapped 2020 Rollout Marred by Pop Star Hacks

Spotify pages for Dua Lipa, Lana Del Rey, Future and others were defaced by an attacker pledging his love for Taylor Swift and Trump.

📖 Read

via "Threat Post".
🕴 Cybersecurity in the Biden Administration: Experts Weigh In 🕴

Security pros and former government employees share their expectations and concerns for the new administration - and their hope for a "return to normal."

📖 Read

via "Dark Reading".
🕴 Open Source Flaws Take Years to Find But Are Quick to Fix 🕴

Companies need to embrace automation and dependency tracking to keep software secure, GitHub says in its annual security report.

📖 Read

via "Dark Reading".
CVE-2020-29280

The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.

📖 Read

via "National Vulnerability Database".
CVE-2020-29287

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-29282

SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.

📖 Read

via "National Vulnerability Database".
CVE-2020-29284

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2020-29285

SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-29283

An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.

📖 Read

via "National Vulnerability Database".
CVE-2020-29288

An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.

📖 Read

via "National Vulnerability Database".
CVE-2020-29279

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

📖 Read

via "National Vulnerability Database".
CVE-2020-26246

Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

📖 Read

via "National Vulnerability Database".
Google Play Apps Remain Vulnerable to High-Severity Flaw

Patches for a flaw (CVE-2020-8913) in the Google Play Core Library have not been implemented by several popular Google Play apps, including Cisco Teams and Edge.

📖 Read

via "Threat Post".
🕴 Google Security Researcher Develops 'Zero-Click' Exploit for iOS Flaw 🕴

A new patched memory corruption vulnerability in Apple's AWDL protocol can be used to take over iOS devices that are in close proximity to an attacker.

📖 Read

via "Dark Reading".
CVE-2020-5676

GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.

📖 Read

via "National Vulnerability Database".
CVE-2020-5677

Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

📖 Read

via "National Vulnerability Database".
CVE-2020-5638

Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.

📖 Read

via "National Vulnerability Database".
CVE-2020-5678

Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

📖 Read

via "National Vulnerability Database".
CVE-2020-5680

Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.

📖 Read

via "National Vulnerability Database".
CVE-2020-5679

Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.

📖 Read

via "National Vulnerability Database".