๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-24496 โ€ผ

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-34575 โ€ผ

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24492 โ€ผ

The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-33526 โ€ผ

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24458 โ€ผ

The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24430 โ€ผ

The Speed Booster Pack รƒยขร…ยกร‚ยก PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24428 โ€ผ

The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24503 โ€ผ

The Popular Brand Icons รƒยขรขโ€šยฌรขโ‚ฌล“ Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24483 โ€ผ

The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24476 โ€ผ

The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24479 โ€ผ

The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24504 โ€ผ

The WP LMS รƒยขรขโ€šยฌรขโ‚ฌล“ Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-34574 โ€ผ

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Multiple Zero-Day Flaws Discovered in Popular Hospital Pneumatic Tube System ๐Ÿ•ด

"PwnedPiper" flaws could allow attackers to disrupt delivery of lab samples or steal hospital employee credentials, new research shows.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2021-37164 โ€ผ

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37160 โ€ผ

A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37216 โ€ผ

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37167 โ€ผ

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37162 โ€ผ

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37166 โ€ผ

A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-20332 โ€ผ

Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default.

๐Ÿ“– Read

via "National Vulnerability Database".