πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2019-25058 β€Ό

An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21179 β€Ό

Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail Magazine Templates and/or transmitted history information may be deleted unintendedly.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25405 β€Ό

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25401 β€Ό

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24407 β€Ό

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23916 β€Ό

Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-24374.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25098 β€Ό

ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3876 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25636 β€Ό

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25638 β€Ό

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44567 β€Ό

An SQL Injection vulnerability exits in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25101 β€Ό

A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25075 β€Ό

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44610 β€Ό

Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44607 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25640 β€Ό

In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3871 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25404 β€Ό

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25838 β€Ό

Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
❌ Microsoft App Store Sizzling with New β€˜Electron Bot’ Malware ❌

The SEO poisoning bot, capable of full system takeover, is actively taking over social media accounts, masquerading as popular games like Temple Run.

πŸ“– Read

via "Threat Post".