πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-47379 β€Ό

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4048 β€Ό

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Breach at US Transportation Department exposes 240,000 employee records πŸ“’

An investigation is underway into the breach, which affected former and current employee data

πŸ“– Read

via "ITPro".
πŸ•΄ Microsoft Advisories Are Getting Worse πŸ•΄

A predictable patch cadence is nice, but the software giant can do more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ TSA Official: Feds Improved Cybersecurity Response Post-Colonial Pipeline πŸ•΄

US Transportation Security Agency (TSA) administrator reflects on how the Colonial Pipeline incident has moved the needle in public-private cooperation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-1549 β€Ό

The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23688 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <=Γ‚ 4.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23674 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in RVOLA WP Original Media Path plugin <=Γ‚ 2.4.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0762 β€Ό

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1915 β€Ό

The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0644 β€Ό

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0600 β€Ό

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1890 β€Ό

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1596 β€Ό

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0892 β€Ό

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31986 β€Ό

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2179 β€Ό

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0490 β€Ό

The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0761 β€Ό

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0233 β€Ό

The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2009 β€Ό

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“– Read

via "National Vulnerability Database".