🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-47141 ‼

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-25618 ‼

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters which will consume the server's resources sufficiently to make it unavailable. There is no ability to view or modify any information.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27498 ‼

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can also make a particular service temporarily unavailable

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-25616 ‼

In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27270 ‼

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources sufficiently to make it unavailable. There is no ability to view or modify any information.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27268 ‼

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.

📖 Read

via "National Vulnerability Database".
🕴 Orgs Have a Long Way to Go in Securing Remote Workforce 🕴

Organizations recognize they are responsible for protecting remote workers from cyber threats, but they have a long way to go in deploying the necessary security technologies.

📖 Read

via "Dark Reading".
🕴 Why Healthcare Boards Lag Other Industries in Preparing for Cyberattacks 🕴

Only by working collaboratively can boards and security leaders make progress and agree about cybersecurity threats and priorities.

📖 Read

via "Dark Reading".
‼ CVE-2022-3678 ‼

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-3680 ‼

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📖 Read

via "National Vulnerability Database".
âš  Linux gets double-quick double-update to fix kernel Oops! âš 

Linux doesn't BSoD. It has oopses and panics instead. (We show you how to make a kernel module to explore further.)

📖 Read

via "Naked Security".
🛠 I2P 2.2.0 🛠

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

📖 Read

via "Packet Storm Security".
🕴 Deepfakes, Synthetic Media: How Digital Propaganda Undermines Trust 🕴

Organizations must educate themselves and their users on how to detect, disrupt, and defend against the increasing volume of online disinformation.

📖 Read

via "Dark Reading".
‼ CVE-2023-27074 ‼

BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1299 ‼

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1396 ‼

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/traveller_details.php. The manipulation of the argument address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222983.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1395 ‼

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been declared as problematic. This vulnerability affects the function query of the file admin/user/list.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222982 is the identifier assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1397 ‼

A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222984.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24180 ‼

Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted elf file.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-27073 ‼

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-1394 ‼

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222981 was assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".