πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-0762 β€Ό

Business Logic Errors in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0763 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0764 β€Ό

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27958 β€Ό

The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26146 β€Ό

Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26149 β€Ό

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22908 β€Ό

SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21708 β€Ό

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43945 β€Ό

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26159 β€Ό

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Bridgestone Americas β€˜disconnects’ manufacturing facilities following β€˜security incident’ πŸ—“οΈ

World’s biggest tire manufacturer yet to determine β€˜scope or nature of any potential incident’

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How to Boost Shift-Left Security in the SDLC πŸ•΄

Organizations will see big wins from applying security controls early in the development life cycle.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24685 β€Ό

HashiCorp Nomad and Nomad Enterprise 1.x before 1.0.17, 1.1.x before 1.1.12, and 1.2.x before 1.2.6 has Uncontrolled Resource Consumption.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24572 β€Ό

Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24571 β€Ό

Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Companies Borrow Attack Technique to Watermark Machine Learning Models πŸ•΄

Researchers continue to improve on a technique for embedded crafted outputs into machine-learning models, an anti-copying technique originally thought up by adversarial researchers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25642 β€Ό

Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24711 β€Ό

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26158 β€Ό

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26156 β€Ό

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action hijacking vulnerabilities arise when an application places user-supplied input into the action URL of an HTML form. An attacker can use this vulnerability to construct a URL that, if visited by another application user, will modify the action URL of a form to point to the attacker's server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44339 β€Ό

David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_transform_scanline() in "/ok_png.c:712".

πŸ“– Read

via "National Vulnerability Database".