πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28733 β€Ό

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28731 β€Ό

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28732 β€Ό

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23681 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25040 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin Ò€” Shortcodes Ultimate plugin <= 5.12.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24399 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Stop Blaming the End User for Security Risk πŸ•΄

Don't count on securing end users for system security. Instead, focus on better securing the systems β€” make them closed by default and build with a security-first approach.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep128: So you want to be a cybercriminal? [Audio + Text] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-25076 β€Ό

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP, TLS or DTLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1725 β€Ό

Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Socura Launches Managed SASE (MSASE) Service πŸ•΄

SASE reduces security & connectivity costs and improves employee experience.

πŸ“– Read

via "Dark Reading".
⚠ Supply chain blunder puts 3CX telephone app users at risk ⚠

Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

πŸ“– Read

via "Naked Security".
πŸ•΄ DataDome Closes $42M in Series C Funding to Advance the Fight Against Bot-Driven Cyberattacks and Fraud πŸ•΄

The investment will fund global commercial rollout and R&D efforts to debilitate fraudsters.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-29059 β€Ό

3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the Electron macOS application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24473 β€Ό

An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Organizations Reassess Cyber Insurance as Self-Insurance Strategies Emerge πŸ•΄

Risk reassessment is shaking up the cybersecurity insurance market, leading some organizations to consider their options, including self-insurance.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-24472 β€Ό

A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30350 β€Ό

Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22845 β€Ό

An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30351 β€Ό

PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded in the PDF file, to be leaked unintentionally. In cases where PDF text objects are present it is possible to copy-paste redacted information into the system clipboard. Once a document is "locked" and marked for redaction once, all redactions performed after this feature is triggered are vulnerable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43473 β€Ό

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".