🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-1762

Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

📖 Read

via "National Vulnerability Database".
CVE-2023-1760

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

📖 Read

via "National Vulnerability Database".
CVE-2023-1258

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

📖 Read

via "National Vulnerability Database".
CVE-2023-28726

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

📖 Read

via "National Vulnerability Database".
CVE-2023-28727

Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.

📖 Read

via "National Vulnerability Database".
👍1
🕴 Post-Quantum Satellite Protection Rockets Towards Reality 🕴

A successful multi-orbit cryptography test beamed quantum-agile data up to two different satellites and back down to Earth.

📖 Read

via "Dark Reading".
CVE-2023-1774

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

📖 Read

via "National Vulnerability Database".
CVE-2023-1771

A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224672.

📖 Read

via "National Vulnerability Database".
CVE-2023-1775

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.

📖 Read

via "National Vulnerability Database".
CVE-2023-1773

A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration File Handler. The manipulation leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224674 is the identifier assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2023-1770

A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affected by this vulnerability is the function get_scale of the file Master.php. The manipulation of the argument perc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224671.

📖 Read

via "National Vulnerability Database".
CVE-2023-1772

A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part of the component Diagram Type Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224673 was assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2023-1777

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

📖 Read

via "National Vulnerability Database".
CVE-2023-1776

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

📖 Read

via "National Vulnerability Database".
🕴 What CISOs Can Do to Build Trust & Fight Fraud in the Metaverse 🕴

Until a degree of confidence is established, a platform's credibility can be eroded by scammers and unsuspecting gamers who fall victim to their attacks.

📖 Read

via "Dark Reading".
🕴 US Space Force Requests $700M for Cybersecurity Blast Off 🕴

Russia's invasion of Ukraine spurs Space Force to seek astronomical investments in cybersecurity.

📖 Read

via "Dark Reading".
🕴 Vulkan Playbook Leak Exposes Russia's Plans for Worldwide Cyberwar 🕴

Russian intelligence services, together with a Moscow-based IT company, are planning worldwide hacking operations that will also enable attacks on critical infrastructure facilities.

📖 Read

via "Dark Reading".
CVE-2023-0343

Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker to decrypt messages.

📖 Read

via "National Vulnerability Database".
CVE-2023-28877

The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)

📖 Read

via "National Vulnerability Database".
CVE-2022-3192

Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.

📖 Read

via "National Vulnerability Database".
CVE-2023-0432

The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.

📖 Read

via "National Vulnerability Database".