πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27475 β€Ό

Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24308 β€Ό

Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43742 β€Ό

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Identifying a Vulnerability in the SAP Software Supply Chain πŸ•΄

Make sure you're using the patch to block this supply chain attack.

πŸ“– Read

via "Dark Reading".
⚠ Hospital robot system gets five critical security holes patched ⚠

Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Git security vulnerabilities prompt updates πŸ—“οΈ

Windows users at highest risk from security bugs in software development tool

πŸ“– Read

via "The Daily Swig".
❌ Feds Shut Down RaidForums Hacking Marketplace ❌

The DoJ is charging its founder, 21-year-old Portuguese citizen Diogo Santos Coelho, on six criminal counts, including conspiracy, access device fraud and aggravated identity theft.

πŸ“– Read

via "Threat Post".
β™ŸοΈ Microsoft Patch Tuesday, April 2022 Edition β™ŸοΈ

Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-28052 β€Ό

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46167 β€Ό

An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26144 β€Ό

An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43741 β€Ό

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27256 β€Ό

An open redirect vulnerability in Hubzilla before version 7.2 allows remote attackers to redirect a logged in user to an arbitrary URL via the rpath parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26643 β€Ό

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

πŸ“– Read

via "National Vulnerability Database".
⚠ US cryptocurrency coder gets 5 years for North Korea sanctions busting ⚠

Cryptocurrency expert didn't take "No" for an answer when the US authorities said he couldn't pursue cryptocoin opps in North Korea.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-22795 β€Ό

A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22794 β€Ό

A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-6834 β€Ό

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0221 β€Ό

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-20107 β€Ό

In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42136 β€Ό

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes Functionality of REDCap 11.2.5 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.

πŸ“– Read

via "National Vulnerability Database".