πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27985 β€Ό

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27984 β€Ό

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27299 β€Ό

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27468 β€Ό

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ API Attacks Soar Amid the Growing Application Surface Area πŸ•΄

With Web application programming interface (API) traffic growing quickly, the average cloud-focused company sees three times more attacks.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Disavowed: Chrome plans to deprecate β€˜document.domain’ lays the groundwork for shift in browser security πŸ—“οΈ

Making document.domain immutable

πŸ“– Read

via "The Daily Swig".
πŸ•΄ CISA Taps Veteran CISO Bob Lord for Technical Adviser Role πŸ•΄

Lord previously spearheaded security for the Democratic National Committee and held leadership roles at companies including Yahoo, Rapid7, and Twitter.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24882 β€Ό

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1173 β€Ό

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23942 β€Ό

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24881 β€Ό

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24883 β€Ό

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Ins and Outs of Secure Infrastructure as Code πŸ•΄

The move to IaC has its challenges but done right can fundamentally improve an organization's overall security posture.

πŸ“– Read

via "Dark Reading".
πŸ” Post-Lapsus$, HHS Warns Healthcare Industry of Insider Threat Risks πŸ”

Following last month's Lapsus$ hacks, federal authorities are reminding healthcare organizations about the danger of insider threats.

πŸ“– Read

via "".
β€Ό CVE-2021-26628 β€Ό

Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as image files.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-36895 β€Ό

Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26629 β€Ό

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern Γ’β‚¬Λœ..\Ò€ℒ.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27854 β€Ό

Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36867 β€Ό

Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher user rights.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1466 β€Ό

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28218 β€Ό

An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

πŸ“– Read

via "National Vulnerability Database".