πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38354 β€Ό

The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38332 β€Ό

The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38329 β€Ό

The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40373 β€Ό

playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38349 β€Ό

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38351 β€Ό

The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38337 β€Ό

The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38340 β€Ό

The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37414 β€Ό

Zoho ManageEngine DesktopCentral version 10.1.2119.7 and prior allows anyone to get a valid user's APIKEY without authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38352 β€Ό

The Feedify Γ’β‚¬β€œ Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38359 β€Ό

The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38355 β€Ό

The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38331 β€Ό

The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38333 β€Ό

The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38336 β€Ό

The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 9/10 πŸ”

The latest Windows zero day, ProtonMail under fire, and creating a more diverse cybersecurity workforce - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
🦿 Remote cybersecurity concerns and labor shortages are front and center in a new small business report 🦿

Despite economic optimism, many companies are concerned about the impacts of the coronavirus pandemic and have temporarily closed as they adapt to new tech tools and work models.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ VMware denies allegations it leaked Confluence RCE exploit πŸ—“οΈ

β€˜Identical’ payload removed from GitHub after researcher’s complaints

πŸ“– Read

via "The Daily Swig".
❌ Yandex Pummeled by Potent Meris DDoS Botnet ❌

Record-breaking distributed denial of service attack targets Russia’s version of Google - Yandex.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-37422 β€Ό

Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ KrebsOnSecurity Hit By Huge New IoT Botnet β€œMeris” β™ŸοΈ

On Thursday evening, KrebsOnSecurity was the subject of a rather massive (and mercifully brief) distributed denial-of-service (DDoS) attack. The assault came from "Meris," the same new "Internet of Things" (IoT) botnet behind record-shattering attacks against Russian search giant Yandex this week and internet infrastructure firm Cloudflare earlier this summer.

πŸ“– Read

via "Krebs on Security".