πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-0715 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0684 β€Ό

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0742 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0741 β€Ό

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43761 β€Ό

Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0740 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0744 β€Ό

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2094 β€Ό

The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0743 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ Why Some Cloud Services Vulnerabilities Are So Hard to Fix πŸ•΄

Five months after AWS customers were alerted about three vulnerabilities, nearly none had plugged the holes. The reasons why underline a need for change.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How to Optimize Your Cyber Insurance Coverage πŸ•΄

From prevention and detection processes to how you handle policy information, having strong cyber insurance coverage can help mitigate cybersecurity attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43765 β€Ό

B&R APROL versions < R 4.2-07 doesnÒ€ℒt process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43764 β€Ό

Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43762 β€Ό

Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43763 β€Ό

Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ DOM XSS vulnerability in Gartner Peer Insights widget patched πŸ—“οΈ

Web attack vector closed after failed fix

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Why ChatGPT Isn't a Death Sentence for Cyber Defenders πŸ•΄

Generative AI combined with user awareness training creates a security alliance that can let organizations work protected from ChatGPT.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2023-0747 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41620 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Mandos Encrypted File System Unattended Reboot Utility 1.8.16 πŸ› 

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

πŸ“– Read

via "Packet Storm Security".
πŸ›  OpenSSL Toolkit 1.1.1t πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer and Transport Layer Security protocols with full-strength cryptography world-wide.

πŸ“– Read

via "Packet Storm Security".