πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-0717 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0722 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0715 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0684 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0742 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0741 β€Ό

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43761 β€Ό

Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0740 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0744 β€Ό

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2094 β€Ό

The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0743 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Why Some Cloud Services Vulnerabilities Are So Hard to Fix πŸ•΄

Five months after AWS customers were alerted about three vulnerabilities, nearly none had plugged the holes. The reasons why underline a need for change.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Optimize Your Cyber Insurance Coverage πŸ•΄

From prevention and detection processes to how you handle policy information, having strong cyber insurance coverage can help mitigate cybersecurity attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43765 β€Ό

B&R APROL versions < R 4.2-07 doesnÒ€ℒt process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43764 β€Ό

Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43762 β€Ό

Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43763 β€Ό

Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ DOM XSS vulnerability in Gartner Peer Insights widget patched πŸ—“οΈ

Web attack vector closed after failed fix

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why ChatGPT Isn't a Death Sentence for Cyber Defenders πŸ•΄

Generative AI combined with user awareness training creates a security alliance that can let organizations work protected from ChatGPT.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2023-0747 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41620 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

πŸ“– Read

via "National Vulnerability Database".