πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Build vs. buy: Is managing Customer Identity slowing your time to market? πŸ“’

Why identity should be top of mind

πŸ“– Read

via "ITPro".
πŸ•΄ Top 5 Data Security RSAC 2023 Sessions to Attend πŸ•΄

A little preconference reconnoitering of upcoming seminars, keynotes, and track sessions makes plotting your days easier. Here's one attendee's list.

πŸ“– Read

via "Dark Reading".
⚠ FBI and FCC warn about β€œJuicejacking” – but just how useful is their advice? ⚠

USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-1331 β€Ό

The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27844 β€Ό

SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0277 β€Ό

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0765 β€Ό

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0764 β€Ό

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1473 β€Ό

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1427 β€Ό

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1282 β€Ό

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44726 β€Ό

The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1274 β€Ό

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1413 β€Ό

The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1723 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection.This issue affects Mobile Assistant: before 21.S.2343.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1371 β€Ό

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0889 β€Ό

Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1325 β€Ό

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1373 β€Ό

The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0367 β€Ό

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27733 β€Ό

DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.

πŸ“– Read

via "National Vulnerability Database".