πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-31047 β€Ό

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32290 β€Ό

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2564 β€Ό

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2565 β€Ό

A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Handler. The manipulation of the argument complaint_type with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228172.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30185 β€Ό

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-30018 β€Ό

Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30257 β€Ό

A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29944 β€Ό

Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-29247 β€Ό

Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ North Korean APT Uses Malicious Microsoft OneDrive Links to Spread New Malware πŸ•΄

ReconShark, aimed at gaining initial access to targeted systems, is a component of previous malware used by the Kimsuky group.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Why the FTX Collapse Was an Identity Problem πŸ•΄

Cryptocurrency has a valuable role to play in a Web3 world β€” but only if the public can fully trust it.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-25052 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <=Γ‚ 1.12.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2575 β€Ό

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by aΓ‚ Stack-based Buffer Overflow vulnerability, which can be triggered by authenticatedΓ‚ users via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25452 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <=Γ‚ 0.2.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2574 β€Ό

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25754 β€Ό

Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45812 β€Ό

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Lees Exxp plugin <=Γ‚ 2.6.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2573 β€Ό

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46799 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <=Γ‚ 1.0.15 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28169 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <=Γ‚ 1.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23668 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP pluginΓ‚ <= 2.25.1 versions.

πŸ“– Read

via "National Vulnerability Database".