๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2021-24603 โ€ผ

The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24591 โ€ผ

The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24599 โ€ผ

The Email Encoder รƒยขรขโ€šยฌรขโ‚ฌล“ Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24395 โ€ผ

The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24513 โ€ผ

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24390 โ€ผ

A proid GET parameter of the WordPressรƒยฆรขโ‚ฌ๏ฟฝร‚ยฏรƒยคร‚ยปร‹ล“รƒยฅร‚ยฎ?Alipay|รƒยจร‚ยดร‚ยขรƒยคร‚ยปร‹ล“รƒยฉรขโ€šยฌร…ยกTenpay|รƒยจร‚ยด?รƒยฅร‚ยฎ?PayPalรƒยฉรขโ‚ฌยบรขโ‚ฌ รƒยฆร‹โ€ ?รƒยฆ?รขโ‚ฌโ„ขรƒยคร‚ยปร‚ยถ WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24392 โ€ผ

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24393 โ€ผ

A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24391 โ€ผ

An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24601 โ€ผ

The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24611 โ€ผ

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24517 โ€ผ

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24568 โ€ผ

The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-24435 โ€ผ

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ Cybersecurity: Watch out for these unique fraudster tricks Loki would be proud of ๐Ÿฆฟ

Online fraud is getting sneakier and stealthier as mischievous operatives evolve their techniques. Learn some of the unique tricks afoot today and how to spot them.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2021-25735 โ€ผ

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3768 โ€ผ

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-32568 โ€ผ

mrdoc is vulnerable to Deserialization of Untrusted Data

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3770 โ€ผ

vim is vulnerable to Heap-based Buffer Overflow

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3766 โ€ผ

objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-25737 โ€ผ

A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

๐Ÿ“– Read

via "National Vulnerability Database".