βΌ CVE-2022-2376 βΌ
π Read
via "National Vulnerability Database".
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated usersπ Read
via "National Vulnerability Database".
βΌ CVE-2022-2830 βΌ
π Read
via "National Vulnerability Database".
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2657 βΌ
π Read
via "National Vulnerability Database".
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRFπ Read
via "National Vulnerability Database".
βΌ CVE-2022-2271 βΌ
π Read
via "National Vulnerability Database".
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)π Read
via "National Vulnerability Database".
βΌ CVE-2022-2083 βΌ
π Read
via "National Vulnerability Database".
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2543 βΌ
π Read
via "National Vulnerability Database".
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layoutsπ Read
via "National Vulnerability Database".
βΌ CVE-2022-2565 βΌ
π Read
via "National Vulnerability Database".
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against adminsπ Read
via "National Vulnerability Database".
βΌ CVE-2022-2775 βΌ
π Read
via "National Vulnerability Database".
The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)π Read
via "National Vulnerability Database".
β Chrome fixes zero-day security hole reported anonymously β update now! β
π Read
via "Naked Security".
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π cryptmount Filesystem Manager 6.0 π
π Read
via "Packet Storm Security".
cryptmount is a utility for creating and managing secure filing systems on GNU/Linux systems. After initial setup, it allows any user to mount or unmount filesystems on demand, solely by providing the decryption password, with any system devices needed to access the filing system being configured automatically. A wide variety of encryption schemes (provided by the kernel dm-crypt system and the libgcrypt library) can be used to protect both the filesystem and the access key. The protected filing systems can reside in either ordinary files or disk partitions. The package also supports encrypted swap partitions, and automatic configuration on system boot-up.π Read
via "Packet Storm Security".
Packetstormsecurity
cryptmount Filesystem Manager 6.0 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π GNUnet P2P Framework 0.17.5 π
π Read
via "Packet Storm Security".
GNUnet is a peer-to-peer framework with focus on providing security. All peer-to-peer messages in the network are confidential and authenticated. The framework provides a transport abstraction layer and can currently encapsulate the network traffic in UDP (IPv4 and IPv6), TCP (IPv4 and IPv6), HTTP, or SMTP messages. GNUnet supports accounting to provide contributing nodes with better service. The primary service build on top of the framework is anonymous file sharing.π Read
via "Packet Storm Security".
Packetstormsecurity
GNUnet P2P Framework 0.17.5 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
ποΈ Squiz Matrix CMS squashes admin account takeover bug ποΈ
π Read
via "The Daily Swig".
IDOR issue meant user account privileges and contact details could be alteredπ Read
via "The Daily Swig".
βΌ CVE-2022-3122 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file medicine_details.php. The manipulation of the argument medicine leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207854 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3121 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The identifier VDB-207853 was assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38367 βΌ
π Read
via "National Vulnerability Database".
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.π Read
via "National Vulnerability Database".
π1
π’ TikTok reportedly suffers data breach π’
π Read
via "ITPro".
However, one researcher inspected some of the files and found it included publicly accessible data which could have been put together without a breachπ Read
via "ITPro".
IT PRO
TikTok reportedly suffers data breach | IT PRO
However, one researcher inspected some of the files and found it included publicly accessible data which could have been put together without a breach
π’ China implies Washington behind University hack π’
π Read
via "ITPro".
Northwestern Polytechnical Universityβs cyber espionage case further strains US-China relationsπ Read
via "ITPro".
IT PRO
China implies Washington behind University hack | IT PRO
Northwestern Polytechnical Universityβs cyber espionage case further strains US-China relations
π’ Microsoft Defender causes 'mass confusion' after legitimate apps trigger ransomware alerts π’
π Read
via "ITPro".
The broken update pushed to users on Sunday morning saw the likes of Teams, Slack, Chrome, and Edge all being confused with the dangerous Hive ransomware payloadsπ Read
via "ITPro".
ITPro
Microsoft Defender causes 'mass confusion' after legitimate apps trigger ransomware alerts
The broken update pushed to users on Sunday morning saw the likes of Teams, Slack, Chrome, and Edge all being confused with the dangerous Hive ransomware payloads
βΌ CVE-2022-2714 βΌ
π Read
via "National Vulnerability Database".
Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2901 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.π Read
via "National Vulnerability Database".
π1
π΄ Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration π΄
π Read
via "Dark Reading".
Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.π Read
via "Dark Reading".
Dark Reading
Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration
Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.
β€1