βΌ CVE-2021-40173 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40178 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40174 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37749 βΌ
π Read
via "National Vulnerability Database".
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.π Read
via "National Vulnerability Database".
βΌ CVE-2021-26084 βΌ
π Read
via "National Vulnerability Database".
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an authenticated user, and in some instances an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if Γ’β¬ΛAllow people to sign up to create their accountΓ’β¬β’ is enabled. To check whether this is enabled go to COG > User Management > User Signup Options. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39117 βΌ
π Read
via "National Vulnerability Database".
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39272 βΌ
π Read
via "National Vulnerability Database".
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39113 βΌ
π Read
via "National Vulnerability Database".
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39111 βΌ
π Read
via "National Vulnerability Database".
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36359 βΌ
π Read
via "National Vulnerability Database".
OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection because reportlab\platypus\paraparser.py (reached via bscw.cgi op=_editfolder.EditFolder) calls eval on attacker-supplied Python code. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38385 βΌ
π Read
via "National Vulnerability Database".
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39271 βΌ
π Read
via "National Vulnerability Database".
OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.π Read
via "National Vulnerability Database".
π¦Ώ How to use phishing simulations and security mailboxes with Microsoft 365's new security model π¦Ώ
π Read
via "Tech Republic".
Microsoft 365's "secure by default" stance removes some tools used by security teams. Here's how to work around the new restrictions.π Read
via "Tech Republic".
TechRepublic
Microsoft 365's new security model: How to use phishing simulations and security mailboxes
Microsoft 365's "secure by default" stance removes some tools used by security teams. Here's how to work around the new restrictions.
β LockBit Gang to Publish 103GB of Bangkok Air Customer Data β
π Read
via "Threat Post".
The airline announced the breach on Thursday, and the ransomware gang started a countdown clock the next day.π Read
via "Threat Post".
Threat Post
LockBit Gang to Publish 103GB of Bangkok Air Customer Data
The airline announced the breach on Thursday, and the ransomware gang started a countdown clock the next day.
βΌ CVE-2021-24580 βΌ
π Read
via "National Vulnerability Database".
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issueπ Read
via "National Vulnerability Database".
βΌ CVE-2021-24437 βΌ
π Read
via "National Vulnerability Database".
The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24528 βΌ
π Read
via "National Vulnerability Database".
The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24593 βΌ
π Read
via "National Vulnerability Database".
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issueπ Read
via "National Vulnerability Database".
βΌ CVE-2021-37911 βΌ
π Read
via "National Vulnerability Database".
The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24581 βΌ
π Read
via "National Vulnerability Database".
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24592 βΌ
π Read
via "National Vulnerability Database".
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedπ Read
via "National Vulnerability Database".