πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-0716 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0739 β€Ό

Race Condition in Switch in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0724 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0685 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin..

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0720 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0717 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0722 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0715 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0684 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0742 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0741 β€Ό

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43761 β€Ό

Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0740 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0744 β€Ό

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2094 β€Ό

The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0743 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Why Some Cloud Services Vulnerabilities Are So Hard to Fix πŸ•΄

Five months after AWS customers were alerted about three vulnerabilities, nearly none had plugged the holes. The reasons why underline a need for change.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Optimize Your Cyber Insurance Coverage πŸ•΄

From prevention and detection processes to how you handle policy information, having strong cyber insurance coverage can help mitigate cybersecurity attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43765 β€Ό

B&R APROL versions < R 4.2-07 doesnÒ€ℒt process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43764 β€Ό

Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43762 β€Ό

Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

πŸ“– Read

via "National Vulnerability Database".