πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41174 β€Ό

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(ΓƒΒ’Γ’β€šΒ¬Γ‹Ε“alert(1)ΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23784 β€Ό

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cloud Data Security Startup Launches πŸ•΄

TrustLogix aims to streamline and simplify data governance in the cloud.

πŸ“– Read

via "Dark Reading".
🦿 Cisco Talos reports new variant of Babuk ransomware targeting Exchange servers 🦿

A new bad actor called Tortilla is running the campaign, and most affected users are in the U.S.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 5 MITRE ATT&CK Tactics Most Frequently Detected by Cisco Secure Firewalls πŸ•΄

Cisco Security examines the most frequently encountered MITRE ATT&CK tactics and techniques.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA Issues New Directive for Patching Known Exploited Vulnerabilities πŸ•΄

The goal is to reduce civilian federal agency exposure to attacks that threat actors are actively using in campaigns, agency says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Researchers Scan the Web to Uncover Malware Infections πŸ•΄

Dozens of companies and universities regularly scan the Internet to gather data on connected devices, but some firms are looking deeper to uncover the extent of detectable malware infections.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-38411 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22960 β€Ό

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43338 β€Ό

In Ericsson Network Location MPS GMPC21, it is possible to creates a new admin user with a SQL Query for file_name in the export functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38420 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38422 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41562 β€Ό

A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38407 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38416 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28416 β€Ό

HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38488 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38403 β€Ό

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41492 β€Ό

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42772 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43339 β€Ό

In Ericsson Network Location MPS GMPC21, it is possible to inject commands via file_name in the export functionality.

πŸ“– Read

via "National Vulnerability Database".