🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-25005

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

📖 Read

via "National Vulnerability Database".
CVE-2021-4164

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

📖 Read

via "National Vulnerability Database".
CVE-2021-24838

The AnyComment WordPress plugin through 0.2.17 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

📖 Read

via "National Vulnerability Database".
CVE-2021-25036

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

📖 Read

via "National Vulnerability Database".
CVE-2022-0240

mruby is vulnerable to NULL Pointer Dereference

📖 Read

via "National Vulnerability Database".
CVE-2021-25037

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected siteâ€s database (e.g., usernames and hashed passwords).

📖 Read

via "National Vulnerability Database".
CVE-2021-25046

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

📖 Read

via "National Vulnerability Database".
CVE-2021-3862

icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

📖 Read

via "National Vulnerability Database".
CVE-2021-25067

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

📖 Read

via "National Vulnerability Database".
CVE-2021-25065

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

📖 Read

via "National Vulnerability Database".
CVE-2022-0256

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

📖 Read

via "National Vulnerability Database".
CVE-2022-0257

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

📖 Read

via "National Vulnerability Database".
CVE-2022-0258

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

📖 Read

via "National Vulnerability Database".
🗓️ Celebrations over REvil ransomware arrests in Russia may be premature 🗓️

‘It’s not clear whether the developers or lower-level criminals were arrested’, threat intel experts tell The Daily Swig

📖 Read

via "The Daily Swig".
CVE-2021-38965

IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.

📖 Read

via "National Vulnerability Database".
CVE-2021-33040

managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.

📖 Read

via "National Vulnerability Database".
CVE-2022-22703

In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.

📖 Read

via "National Vulnerability Database".
CVE-2022-0245

Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.

📖 Read

via "National Vulnerability Database".
CVE-2021-44757

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

📖 Read

via "National Vulnerability Database".
🗓️ Researchers discover ‘extremely easy’ 2FA bypass in Box cloud management software 🗓️

Breaking the Box

📖 Read

via "The Daily Swig".
Organizations Face a ‘Losing Battle’ Against Vulnerabilities

Companies must take more ‘innovative and proactive’ approaches to security in 2022 to combat threats that emerged last year, researchers said.

📖 Read

via "Threat Post".