‼ CVE-2022-0400 ‼
📖 Read
via "National Vulnerability Database".
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-0367 ‼
📖 Read
via "National Vulnerability Database".
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.📖 Read
via "National Vulnerability Database".
⚠ Firefox 104 is out – no critical bugs, but update anyway ⚠
📖 Read
via "Naked Security".
Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.📖 Read
via "Naked Security".
Sophos News
Naked Security – Sophos News
⚠ LastPass source code breach – do we still recommend password managers? ⚠
📖 Read
via "Naked Security".
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?📖 Read
via "Naked Security".
Naked Security
LastPass source code breach – do we still recommend password managers?
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?
🕴 3 Ways No-Code Developers Can Shoot Themselves in the Foot 🕴
📖 Read
via "Dark Reading".
Low/no-code tools allow citizen developers to design creative solutions to address immediate problems, but without sufficient training and oversight, the technology can make it easy to make security mistakes.📖 Read
via "Dark Reading".
Dark Reading
3 Ways No-Code Developers Can Shoot Themselves in the Foot
Low/no-code tools allow citizen developers to design creative solutions to address immediate problems, but without sufficient training and oversight, the technology can make it easy to make security mistakes.
‼ CVE-2022-27547 ‼
📖 Read
via "National Vulnerability Database".
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36034 ‼
📖 Read
via "National Vulnerability Database".
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36033 ‼
📖 Read
via "National Vulnerability Database".
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27546 ‼
📖 Read
via "National Vulnerability Database".
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27558 ‼
📖 Read
via "National Vulnerability Database".
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.📖 Read
via "National Vulnerability Database".
🔏 Consumer Financial Protection Bureau Reasserts Importance of Data Protection 🔏
📖 Read
via "".
Organizations with poor data security could be found in violation of the Consumer Financial Protection Act's prohibition on unfair acts or practices.📖 Read
via "".
🕴 Receipt for €8M iOS Zero-Day Sale Pops Up on Dark Web 🕴
📖 Read
via "Dark Reading".
Documents appear to show that Israeli spyware company Intellexa sold a full suite of services around a zero-day affecting both Android and iOS ecosystems.📖 Read
via "Dark Reading".
Dark Reading
Receipt for €8M iOS Zero-Day Sale Pops Up on Dark Web
Documents appear to show that Israeli spyware company Intellexa sold a full suite of services around a zero-day affecting both Android and iOS ecosystems.
🤯2
‼ CVE-2022-2261 ‼
📖 Read
via "National Vulnerability Database".
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2537 ‼
📖 Read
via "National Vulnerability Database".
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2267 ‼
📖 Read
via "National Vulnerability Database".
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2080 ‼
📖 Read
via "National Vulnerability Database".
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2638 ‼
📖 Read
via "National Vulnerability Database".
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2599 ‼
📖 Read
via "National Vulnerability Database".
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2034 ‼
📖 Read
via "National Vulnerability Database".
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2373 ‼
📖 Read
via "National Vulnerability Database".
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36036 ‼
📖 Read
via "National Vulnerability Database".
mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s) 1.3.0 and 2.0.0-rc2. There are currently no known workarounds.📖 Read
via "National Vulnerability Database".