πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-24189 β€Ό

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34249 β€Ό

SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2021-34167 β€Ό

Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ The UN's cyber crime treaty could be a privacy disaster πŸ“’

Although a UN committee is fleshing out a new international cyber crime treaty, experts question whether it’ll make any positive difference to businesses

πŸ“– Read

via "ITPro".
πŸ“’ LockBit leaks 44GB of Royal Mail's data, new Β£33m ransom set πŸ“’

200 employees are believed to be affected with vaccine records, salary information, HR formal dismissal documents, and business contract documents all appearing to be included in the leak

πŸ“– Read

via "ITPro".
πŸ‘3
β€Ό CVE-2023-1035 β€Ό

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been classified as critical. Affected is an unknown function of the file update_user.php. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221784.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2024 β€Ό

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-26550 β€Ό

A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-48362 β€Ό

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2023-26091 β€Ό

The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-25105 β€Ό

A vulnerability, which was classified as problematic, was found in dro.pm. This affects an unknown part of the file web/fileman.php. The manipulation of the argument secret/key leads to cross site scripting. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is fa73c3a42bc5c246a1b8f815699ea241aef154bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221763.

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2021-3329 β€Ό

Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-1048 β€Ό

A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipulation leads to improper initialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221807.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1043 β€Ό

A vulnerability was found in MuYuCMS 2.2. It has been classified as problematic. Affected is an unknown function of the file /editor/index.php. The manipulation of the argument dir_path leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221802 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1045 β€Ό

A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.php/accessory/filesdel.html. The manipulation of the argument filedelur leads to relative path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221804.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1046 β€Ό

A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221805 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1042 β€Ό

A vulnerability has been found in SourceCodester Online Pet Shop We App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /pet_shop/admin/orders/update_status.php. The manipulation of the argument oid with the input 1"><script>alert(1111)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221800.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1044 β€Ό

A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /editor/index.php. The manipulation of the argument file_path leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221803.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1047 β€Ό

A vulnerability classified as critical was found in TechPowerUp RealTemp 3.7.0.0. This vulnerability affects unknown code in the library WinRing0x64.sys. The manipulation leads to improper initialization. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-221806 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26602 β€Ό

ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48363 β€Ό

In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1