🕴 Getting Ahead of Supply Chain Attacks 🕴
📖 Read
via "Dark Reading".
Attackers are willing to replicate entire networks, purchase domains, and persist for months, not to mention spend significantly to make these campaigns successful.📖 Read
via "Dark Reading".
Dark Reading
Getting Ahead of Supply Chain Attacks
Attackers are willing to replicate entire networks, purchase domains, and persist for months, not to mention spend significantly to make these campaigns successful.
‼ CVE-2022-2240 ‼
📖 Read
via "National Vulnerability Database".
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2072 ‼
📖 Read
via "National Vulnerability Database".
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29709 ‼
📖 Read
via "National Vulnerability Database".
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2189 ‼
📖 Read
via "National Vulnerability Database".
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2115 ‼
📖 Read
via "National Vulnerability Database".
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2071 ‼
📖 Read
via "National Vulnerability Database".
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2341 ‼
📖 Read
via "National Vulnerability Database".
The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2340 ‼
📖 Read
via "National Vulnerability Database".
The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2219 ‼
📖 Read
via "National Vulnerability Database".
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1551 ‼
📖 Read
via "National Vulnerability Database".
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2299 ‼
📖 Read
via "National Vulnerability Database".
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1539 ‼
📖 Read
via "National Vulnerability Database".
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0594 ‼
📖 Read
via "National Vulnerability Database".
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0899 ‼
📖 Read
via "National Vulnerability Database".
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2239 ‼
📖 Read
via "National Vulnerability Database".
The Request a Quote WordPress plugin through 2.3.7 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.📖 Read
via "National Vulnerability Database".
🗓️ Cisco patches dangerous bug trio in Nexus Dashboard 🗓️
📖 Read
via "The Daily Swig".
Inadequate access control and CSRF protections spawn critical and high severity issues📖 Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Cisco patches dangerous bug trio in Nexus Dashboard
Inadequate access control and CSRF protections spawn critical and high severity issues
🕴 Aqua Launches Out-of-the-Box Runtime Security with Advanced Protection against the Most Sophisticated Threats 🕴
📖 Read
via "Dark Reading".
Security professionals can now achieve real-time protection for their workloads in minutes.📖 Read
via "Dark Reading".
Dark Reading
Aqua Launches Out-of-the-Box Runtime Security with Advanced Protection against the Most Sophisticated Threats
Security professionals can now achieve real-time protection for their workloads in minutes.
‼ CVE-2022-1312 ‼
📖 Read
via "National Vulnerability Database".
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-33965 ‼
📖 Read
via "National Vulnerability Database".
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28441 ‼
📖 Read
via "National Vulnerability Database".
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.📖 Read
via "National Vulnerability Database".