πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-38843 β€Ό

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38823 β€Ό

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38808 β€Ό

ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38827 β€Ό

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3176 β€Ό

There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42949 β€Ό

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38844 β€Ό

CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38845 β€Ό

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38831 β€Ό

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38829 β€Ό

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38826 β€Ό

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38830 β€Ό

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38832 β€Ό

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Botched Crypto Mugging Lands Three U.K. Men in Jail β™ŸοΈ

Three men in the United Kingdom were arrested this month after police responding to an attempted break-in at a residence stopped their car as they fled the scene. The authorities found weapons and a police uniform in the trunk, and say the trio intended to assault a local man and force him to hand over virtual currencies. 

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2022-35193 β€Ό

TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40337 β€Ό

OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38878 β€Ό

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42597 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , Apache 2.4.14, SURMS V 1.0 via the Add New Tenant List Rent List form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3225 β€Ό

Improper Access Control in GitHub repository budibase/budibase prior to 1.3.20.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38409 β€Ό

Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42948 β€Ό

HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.

πŸ“– Read

via "National Vulnerability Database".