๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-38665 โ€ผ

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36341 โ€ผ

Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS รขโ‚ฌโ€œ Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37112 โ€ผ

BlueCMS 1.6 has SQL injection in line 55 of admin/model.php

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37111 โ€ผ

BlueCMS 1.6 has SQL injection in line 132 of admin/article.php

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38172 โ€ผ

ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-1513 โ€ผ

A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-35115 โ€ผ

IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38463 โ€ผ

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38132 โ€ผ

Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction arguments, allowing URL redirection to an arbitrary server, downloading an arbitrary script file, and eventually executing the file in the device. This issue affects: Linksys MR8300 Router 1.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36945 โ€ผ

The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-25903 โ€ผ

The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-24375 โ€ผ

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38089 โ€ผ

Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37333 โ€ผ

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37305 โ€ผ

The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38080 โ€ผ

Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37418 โ€ผ

The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchronization after capturing two consecutive valid key fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38078 โ€ผ

Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ—“๏ธ Stop, press: Fragmented vendor ecosystem leaves media industry increasingly vulnerable to software supply chain threats ๐Ÿ—“๏ธ

New study highlights the myriad cyber defense challenges faced by media companies in 2022

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ‘1
๐Ÿ›  MIMEDefang Email Scanner 3.1 ๐Ÿ› 

MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. Includes the ability to do many other kinds of mail processing, such as replacing parts of messages with URLs. It can alter or delete various parts of a MIME message according to a very flexible configuration file. It can also bounce messages with unacceptable attachments. MIMEDefang works with the Sendmail 8.11 and newer "Milter" API, which makes it more flexible and efficient than procmail-based approaches.

๐Ÿ“– Read

via "Packet Storm Security".
โ€ผ CVE-2022-36633 โ€ผ

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

๐Ÿ“– Read

via "National Vulnerability Database".