๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-26245 โ€ผ

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the version check in order to install any firmware version (e.g., newer, older, or customized). This indirectly allows an attacker to install custom firmware in the IVI system.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2297 โ€ผ

The Profile Builder รขโ‚ฌโ€œ User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-22901 โ€ผ

ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administratorรขโ‚ฌโ„ขs privilege can exploit this vulnerability to access arbitrary system files.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2323 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28770 โ€ผ

The sensitive information exposure vulnerability in the CGI รขโ‚ฌล“Export_Logรขโ‚ฌ๏ฟฝ and the binary รขโ‚ฌล“zcmdรขโ‚ฌ๏ฟฝ in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ“ข Microsoft links PaperCut server attacks to Cl0p, LockBit ransomware ๐Ÿ“ข

Microsoft Threat Intelligence noted attacks were facilitated by GoAnywhere vulnerabilities and the Raspberry Robin worm

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2023-1778 โ€ผ

This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems.The vulnerability has been addressed by forcing the user to change their default password to a new non-default password.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2327 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2328 โ€ผ

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Combating Kubernetes โ€” the Newest IAM Challenge ๐Ÿ•ด

IT leaders need to ensure Kubernetes clusters don't become a gateway for cybercriminals.

๐Ÿ“– Read

via "Dark Reading".
โค1
โ€ผ CVE-2023-2336 โ€ผ

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29255 โ€ผ

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2339 โ€ผ

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โš  Google leaking 2FA secrets โ€“ researchers advise against new โ€œaccount syncโ€ feature for now โš 

You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

๐Ÿ“– Read

via "Naked Security".
โ€ผ CVE-2023-2344 โ€ผ

A vulnerability has been found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227587.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30847 โ€ผ

H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream URL by reading from uninitialized pointer. This behavior can lead to crashes or leak of information to back end HTTP servers. Pull request number 3229 fixes the issue. The pull request has been merged to the `master` branch in commit f010336. Users should upgrade to commit f010336 or later.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2341 โ€ผ

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24966 โ€ผ

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2347 โ€ผ

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/services/manage_service.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227590 is the identifier assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30338 โ€ผ

Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1