🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2021-4421 ‼

The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-36760 ‼

The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-36757 ‼

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33900 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33890 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-3092 ‼

The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping when the 'Save Data SendMail' feature is enabled. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-30932 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-30926 ‼

In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33886 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-30928 ‼

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-3106 ‼

A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-3135 ‼

The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-2517 ‼

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the permalink_setup function. This makes it possible for unauthenticated attackers to change the permalink structure via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. While nonce verification is implemented, verification only takes place when a nonce is provided.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-4420 ‼

The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the sell_media_process() function. This makes it possible for unauthenticated attackers to sell media paypal orders via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-2763 ‼

Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF file.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-30940 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33893 ‼

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33889 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33883 ‼

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33892 ‼

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-3011 ‼

The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. This is due to missing or incorrect nonce validation on the arm_check_user_cap function. This makes it possible for unauthenticated attackers to perform multiple unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

📖 Read

via "National Vulnerability Database".