๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โŒ SOVA, Worryingly Sophisticated Android Trojan, Takes Flight โŒ

The malware appeared in August with an ambitious roadmap (think ransomware, DDoS) that could make it 'the most feature-rich Android malware on the market.'

๐Ÿ“– Read

via "Threat Post".
โ€ผ CVE-2021-38341 โ€ผ

The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38338 โ€ผ

The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38353 โ€ผ

The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38339 โ€ผ

The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.01.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38330 โ€ผ

The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38354 โ€ผ

The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38332 โ€ผ

The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38329 โ€ผ

The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-40373 โ€ผ

playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38349 โ€ผ

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38351 โ€ผ

The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38337 โ€ผ

The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38340 โ€ผ

The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-37414 โ€ผ

Zoho ManageEngine DesktopCentral version 10.1.2119.7 and prior allows anyone to get a valid user's APIKEY without authentication.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38352 โ€ผ

The Feedify รขโ‚ฌโ€œ Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38359 โ€ผ

The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38355 โ€ผ

The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38331 โ€ผ

The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38333 โ€ผ

The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-38336 โ€ผ

The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

๐Ÿ“– Read

via "National Vulnerability Database".