πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2018-1000891 β€Ό

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28074 β€Ό

SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-1000893 β€Ό

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13969 β€Ό

CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28070 β€Ό

SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2018-1000892 β€Ό

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-13968 β€Ό

CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Why Your Organization's Security Maturity Matters – And What to Do About It πŸ”

Forrester’s practical and actionable Informational Security Maturity Model - and Digital Guardian - can help organizations gauge their information security program.

πŸ“– Read

via "Digital Guardian".
πŸ•΄ White Ops Announces Its Acquisition πŸ•΄

A group including Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon has purchased the human verification technology company.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft, McAfee, Rapid7, and Others Form New Ransomware Task Force πŸ•΄

Industry group wants to get a framework in the hands of the new administration's cybersecurity officials by early spring 2021.

πŸ“– Read

via "Dark Reading".
🦿 Android security: The last piece of advice you'll need for 2020 🦿

Jack Wallen takes one more opportunity to remind Android device owners to use those phones with a great deal of caution, otherwise they could become victims of malware.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2020-35668 β€Ό

RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5684 β€Ό

iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2499 β€Ό

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35669 β€Ό

An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35676 β€Ό

BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can input a crafted payload that will execute upon the application's administrator browsing the registered users' list. Once the arbitrary Javascript is executed in the context of the admin, this will cause the attacker to gain administrative privileges, effectively leading into an application takeover. This affects app/membership_signup.php and app/admin/pageViewMembers.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35677 β€Ό

BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. The caveat here is that an attacker would need administrative privileges in order to create the payload. One might think this completely mitigates the privilege-escalation impact as there is only one high-privileged role. However, it was discovered that the endpoint responsible for creating the group lacks CSRF protection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2503 β€Ό

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2504 β€Ό

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5681 β€Ό

Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-2505 β€Ό

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

πŸ“– Read

via "National Vulnerability Database".