πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-2336 β€Ό

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29255 β€Ό

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2339 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

πŸ“– Read

via "National Vulnerability Database".
⚠ Google leaking 2FA secrets – researchers advise against new β€œaccount sync” feature for now ⚠

You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-2344 β€Ό

A vulnerability has been found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227587.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30847 β€Ό

H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream URL by reading from uninitialized pointer. This behavior can lead to crashes or leak of information to back end HTTP servers. Pull request number 3229 fixes the issue. The pull request has been merged to the `master` branch in commit f010336. Users should upgrade to commit f010336 or later.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2341 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24966 β€Ό

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2347 β€Ό

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/services/manage_service.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227590 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30338 β€Ό

Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-2346 β€Ό

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227589 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2343 β€Ό

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30349 β€Ό

JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2348 β€Ό

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227591.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2342 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2345 β€Ό

A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may be launched remotely. The identifier of this vulnerability is VDB-227588.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep132: Proof-of-concept lets anyone hack at will ⚠

When Doug says, "Happy Remote Code Execution Day, Duck"... it's irony. For the avoidance of all doubt :-)

πŸ“– Read

via "Naked Security".
πŸ•΄ Continuous Scanning Is Imperative for Effective Web Application Security πŸ•΄

New research from Invicti shows that an increase in security scanning cadence contributes to improved security posture over time.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The White House National Cybersecurity Strategy Has a Fatal Flaw πŸ•΄

The government needs to shift focus and reconsider how it thinks about securing our nation's digital and physical assets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ SANS Reveals Top 5 Most Dangerous Cyberattacks for 2023 πŸ•΄

SEO-aided attacks, developer targeting, and malicious use of AI top the list for 2023.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-30848 β€Ό

Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually.

πŸ“– Read

via "National Vulnerability Database".