πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ White House tackles β€˜unique security challenges’ faced by open source ecosystem during dedicated virtual summit πŸ—“οΈ

Silicon Valley giants joined government officials to thrash out remedies to software supply chain woes

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-25025 β€Ό

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25024 β€Ό

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25061 β€Ό

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0253 β€Ό

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24909 β€Ό

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25005 β€Ό

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4164 β€Ό

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24838 β€Ό

The AnyComment WordPress plugin through 0.2.17 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25036 β€Ό

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldnΓƒΒ’Γ’β€šΒ¬Γ’β€žΒ’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0240 β€Ό

mruby is vulnerable to NULL Pointer Dereference

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25037 β€Ό

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected siteÒ€ℒs database (e.g., usernames and hashed passwords).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25046 β€Ό

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3862 β€Ό

icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25067 β€Ό

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25065 β€Ό

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0256 β€Ό

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0257 β€Ό

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0258 β€Ό

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Celebrations over REvil ransomware arrests in Russia may be premature πŸ—“οΈ

β€˜It’s not clear whether the developers or lower-level criminals were arrested’, threat intel experts tell The Daily Swig

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-38965 β€Ό

IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.

πŸ“– Read

via "National Vulnerability Database".