πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-45668 β€Ό

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45645 β€Ό

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45646 β€Ό

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45649 β€Ό

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3591 β€Ό

Use After Free in GitHub repository vim/vim prior to 9.0.0789.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46145 β€Ό

authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery, this can be used to overwrite the email address of admin accounts and take over their accounts. authentik 2022.11.2 and 2022.10.2 fix this issue. As a workaround, a policy can be created and bound to the `default-user-settings-flow flow` with the contents `return request.user.is_authenticated`.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Newsroom Sues NSO Group for Pegasus Spyware Compromise πŸ•΄

Journalists in El Salvador haul NSO Group to US court for illegal surveillance that ultimately compromised their safety.

πŸ“– Read

via "Dark Reading".
⚠ Apple pushes out iOS security update that’s more tight-lipped than ever ⚠

We grabbed the update, based on no information at all, just in case we came across a reason to advise you not to. So far, so good...

πŸ“– Read

via "Naked Security".
⚠ LastPass admits to customer data breach caused by previous breach ⚠

Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-44959 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3086 β€Ό

An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1.1, UC-8540 Series V1.0 to V1.2, UC-8410A Series V2.2, UC-8200 Series V1.0 to V2.4, UC-8100A-ME-T Series V1.0 to V1.1, UC-8100 Series V1.2 to V1.3, UC-5100 Series V1.2, UC-3100 Series V1.2 to V2.0, UC-2100 Series V1.3 to V1.5, and UC-2100-W Series V1.3 to V1.5 can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the deviceÒ€ℒs authentication files to create a new user and gain full access to the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44956 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44950 β€Ό

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44962 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44957 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44948 β€Ό

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44291 β€Ό

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44945 β€Ό

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44949 β€Ό

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44960 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44953 β€Ό

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

πŸ“– Read

via "National Vulnerability Database".