πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41647 β€Ό

An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41649 β€Ό

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41648 β€Ό

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3825 β€Ό

On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29109 β€Ό

A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the userÒ€ℒs browser.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Friday Five 10/1 πŸ”

Android scam apps, how insider threats can cause damage, and combating SIM swap attacks - catch up on the week's infosec news with the Friday Five!

πŸ“– Read

via "".
β€Ό CVE-2021-41461 β€Ό

Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41462 β€Ό

Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40921 β€Ό

Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40925 β€Ό

Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40968 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40975 β€Ό

Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40970 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40973 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40971 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40923 β€Ό

Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40927 β€Ό

Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40928 β€Ό

Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40969 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40926 β€Ό

Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40972 β€Ό

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.

πŸ“– Read

via "National Vulnerability Database".