πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-24775 β€Ό

The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24763 β€Ό

The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24919 β€Ό

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46253 β€Ό

A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24944 β€Ό

The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24900 β€Ό

The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24707 β€Ό

The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25072 β€Ό

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24765 β€Ό

The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0417 β€Ό

Heap-based Buffer Overflow in Conda vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24983 β€Ό

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ SureMDM bug chain enabled wholesale compromise of managed devices πŸ—“οΈ

Series of flaws in MDM platform addressed in web console and Linux agent

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Mastercard Launches Global Cybersecurity Alliance Program to Further Secure The Digital Ecosystem πŸ•΄

New program helps partners accelerate growth and provide scaled delivery of critical cybersecurity and risk services.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Qualys Adds Advanced Remediation Capabilities to Minimize Vulnerability Risk πŸ•΄

Update to Qualys Cloud Platform enables organizations to fix asset misconfigurations in addition to patching to achieve comprehensive remediation.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Critical Samba flaw presents code execution threat πŸ—“οΈ

Urgent patching of file-sharing technology urged

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-38560 β€Ό

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44746 β€Ό

UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.

πŸ“– Read

via "National Vulnerability Database".
⚠ Website operator fined for using Google Fonts β€œthe cloudy way” ⚠

Google Fonts are OK, it seems, but only if everyone keeps their own copy of the fonts they use.

πŸ“– Read

via "Naked Security".
πŸ•΄ Complexity vs. Capability: How to Bridge the Security Effectiveness Gap πŸ•΄

Consolidation and automation are among the strategies for balancing security complexity and capability.

πŸ“– Read

via "Dark Reading".
⚠ Linux kernel patches β€œperformance can be harmful” bug in video driver ⚠

This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

πŸ“– Read

via "Naked Security".
πŸ•΄ 7 Red Flags That Can Stop Your Company From Becoming a Unicorn πŸ•΄

Investors and venture capitalists share the reasons that make them turn away from investing in your security tech.

πŸ“– Read

via "Dark Reading".