πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1221 β€Ό

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1320 β€Ό

The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1268 β€Ό

The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1298 β€Ό

The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1014 β€Ό

The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0346 β€Ό

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1093 β€Ό

The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-0781 β€Ό

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1192 β€Ό

The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42586 β€Ό

A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29599 β€Ό

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1825 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42585 β€Ό

A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28874 β€Ό

Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.

πŸ“– Read

via "National Vulnerability Database".
❌ Zero Trust for Data Helps Enterprises Detect, Respond and Recover from Breaches ❌

Mohit Tiwari, CEO of Symmetry Systems, explores Zero Trust, data objects and the NIST framework for cloud and on-prem environments.

πŸ“– Read

via "Threat Post".
⚠ Clearview AI face-matching service fined a lot less than expected ⚠

The fine has finally gone through... but it's less than 45% of what was originally proposed.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Blockchain bridge Wormhole pays record $10m bug bounty reward πŸ—“οΈ

Critical security flaw patched on the same day it was submitted

πŸ“– Read

via "The Daily Swig".
πŸ•΄ After the Okta Breach, Diversify Your Sources of Truth πŸ•΄

What subsequent protections do you have in place when your first line of defense goes down?

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Yik Yak fixes information disclosure bug that leaked users’ GPS location πŸ—“οΈ

Hairy MitM exploit independently discovered by two security researchers

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-1817 β€Ό

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1816 β€Ό

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

πŸ“– Read

via "National Vulnerability Database".