πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28892 β€Ό

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1514 β€Ό

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22441 β€Ό

IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29413 β€Ό

Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress via &title parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29410 β€Ό

Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38952 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27860 β€Ό

Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29585 β€Ό

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22427 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine πŸ•΄

Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.

πŸ“– Read

via "Dark Reading".
πŸ” The Most Exploited Vulnerabilities of 2021 πŸ”

U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities say these vulnerabilities were targeted the most by hackers last year.

πŸ“– Read

via "".
πŸ•΄ Capital One Ventures, Snowflake Ventures, Verizon Ventures, and Wipro Ventures Join Securonix $1B+ Growth Investment as Strategic Investors πŸ•΄

Blue Chip Companies Deepen Commitment Based on Success of Long-Standing Customer and Partner Relationships and Conviction of Securonix’s Vision and Hypergrowth Potential

πŸ“– Read

via "Dark Reading".
πŸ•΄ IT Teams Worry Staff Lack Cloud-Specific Skills πŸ•΄

Security, cost, and reliability top the list of concerns IT teams have about their cloud operations, according to a recent report.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL πŸ•΄

Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29555 β€Ό

The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29081 β€Ό

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24449 β€Ό

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28477 β€Ό

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28454 β€Ό

Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24898 β€Ό

org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28060 β€Ό

SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.

πŸ“– Read

via "National Vulnerability Database".