πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40190 β€Ό

SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in usersÒ€ℒ browsers and steal sensitive information, including user credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3784 β€Ό

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3785 β€Ό

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40291 β€Ό

The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41680 β€Ό

Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'search[value] parameter in the appLms/ajax.server.php?r=mycertificate/getMyCertificates' function in order to dump the entire database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43752 β€Ό

** UNSUPPORTED WHEN ASSIGNED ** Oracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation vulnerability. A low privileged user can escalate to root by crafting a malicious printer and double clicking on the the crafted printer's icon.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42925 β€Ό

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

πŸ“– Read

via "National Vulnerability Database".
⚠ Psychotherapy extortion suspect: arrest warrant issued ⚠

Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.

πŸ“– Read

via "Naked Security".
πŸ‘1
β€Ό CVE-2021-27784 β€Ό

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Australia's Department of Defence becomes latest victim of regional ransomware attacks πŸ“’

Military information was not stolen in the breach, which may affect the records of 40,000 defence personnel

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ“’ MSPs' next biggest investment will be in MDR and dark web monitoring πŸ“’

Research showed that providers were torn on the decisions of what their next big offering will be

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-43354 β€Ό

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2572 β€Ό

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3373 β€Ό

Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41552 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components) allows Server Side Request Forgery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43353 β€Ό

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41553 β€Ό

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36605 β€Ό

Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3191 β€Ό

Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allows local users to gain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3370 β€Ό

Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44542 β€Ό

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

πŸ“– Read

via "National Vulnerability Database".