‼ CVE-2021-40975 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40970 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40973 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40971 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40923 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40927 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40928 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40969 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40926 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40972 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40922 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the last_name parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41464 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40924 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the first_name parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41463 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41465 ‼
📖 Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.📖 Read
via "National Vulnerability Database".
🦿 Consumer privacy study finds online privacy is of growing concern to increasingly more people 🦿
📖 Read
via "Tech Republic".
The study, from Cisco, comes with the announcement of its New Trust Standard, a benchmark for seeing how trustworthy businesses are as they embrace digital transformation.📖 Read
via "Tech Republic".
🕴 4.6M Neiman Marcus Online Customers Alerted to Data Breach 🕴
📖 Read
via "Dark Reading".
The breach occurred in May 2020.📖 Read
via "Dark Reading".
Dark Reading
4.6M Neiman Marcus Online Customers Alerted to Data Breach
The breach occurred in May 2020.
🦿 Lawsuit claims ransomware attack caused fatal injury to infant at Alabama hospital 🦿
📖 Read
via "Tech Republic".
Fetal heartbeat monitors were down in the labor and delivery wards, which the lawsuit claims resulted in a baby being born with brain damage.📖 Read
via "Tech Republic".
TechRepublic
Lawsuit claims ransomware attack caused fatal injury to infant at Alabama hospital
Fetal heartbeat monitors were down in the labor and delivery wards, which the lawsuit claims resulted in a baby being born with brain damage.
🕴 Why Windows Print Spooler Remains a Big Attack Target 🕴
📖 Read
via "Dark Reading".
Despite countless vulnerabilities and exploits, the legacy Windows printing process service continues to be an attack surface in constant need of repair and maintenance, security experts say.📖 Read
via "Dark Reading".
Dark Reading
Why Windows Print Spooler Remains a Big Attack Target
Despite countless vulnerabilities and exploits, the legacy Windows printing process service continues to be an attack surface in constant need of repair and maintenance, security experts say.
🕴 Companies Face Issues as Let's Encrypt Root Certificate Expires 🕴
📖 Read
via "Dark Reading".
Experts warn devices will be affected after major HTTPS certificate provider Let's Encrypt saw its root certificate expire this week.📖 Read
via "Dark Reading".
Dark Reading
Companies Face Issues as Let's Encrypt Root Certificate Expires
Experts warn devices will be affected after major HTTPS certificate provider Let's Encrypt saw its root certificate expire this week.
❌ MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed ❌
📖 Read
via "Threat Post".
Coinbase suspects phishing led to attackers getting personal details needed to access wallets but also blamed a flaw in its SMS-based 2FA.📖 Read
via "Threat Post".
Threat Post
MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed
Coinbase suspects phishing led to attackers getting personal details needed to access wallets but also blamed a flaw in its SMS-based 2FA.