🛡 Cybersecurity & Privacy 🛡 - News
25.1K subscribers
88.5K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-41524 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41520 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41522 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41517 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-40161 ‼

Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41521 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41525 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41518 ‼

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41294 ‼

IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42457 ‼

Generex CS141 before 2.08 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-39279 ‼

discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-27810 ‼

It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-39284 ‼

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not affect session cookies. Users are advised to upgrade to v4.2.7 or later. Users unable to upgrade are advised to manually construct their cookies either by setting the options in code or by constructing Cookie objects. Examples of each workaround are available in the linked GHSA.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41355 ‼

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-26236 ‼

The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-26238 ‼

The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-40494 ‼

NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

📖 Read

via "National Vulnerability Database".
🕴 Sharing Knowledge at 44CON 🕴

The infosec conference named after the UK's calling code returned this year with a focus on building a healthy community.

📖 Read

via "Dark Reading".
📢 China cracks down on citizens' anti-censorship tools with Great Firewall upgrades 📢

This new discovery comes a week before a predicted major reshuffle of leadership in the Chinese Communist Party

📖 Read

via "ITPro".
📢 Sophos 2021 Antivirus solutions review 📢

Low-cost consumer security products for Mac and Windows

📖 Read

via "ITPro".
📢 Canadian Netwalker ransomware affiliate faces 20 years in prison and $21.5 million fine 📢

The Canadian hacker was arrested in Quebec after a search revealed 719 Bitcoin and hundreds of thousands of Canadian dollars believed to be stolen funds

📖 Read

via "ITPro".