πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-37415 β€Ό

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.Patching on top of CVE-2023-35797BeforeΓ‚ 6.1.2Γ‚ the proxy_user option can also inject semicolon.This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3319 β€Ό

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay DS allows Stored XSS.This issue affects PlatPlay DS: before 3.14.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35069 β€Ό

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal.This issue affects Bullwark: before BLW-2016E-960H.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2957 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Florist Site allows SQL Injection.This issue affects Florist Site: before 3.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1547 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection.This issue affects Parkmatik: before 02.01-a51.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29449 β€Ό

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29450 β€Ό

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ β€˜Big game ransomware’ tactics return as attackers eye lucrative payouts πŸ“’

Small businesses aren’t out of the firing line, but big business is facing a new wave as operators take gambles

πŸ“– Read

via "ITPro".
❀1πŸ‘1
β€Ό CVE-2023-29454 β€Ό

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29456 β€Ό

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23585 β€Ό

Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22435 β€Ό

Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24480 β€Ό

Controller DoS due to stack overflow when decoding a message from the server

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29452 β€Ό

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field Ò€œAttribution textҀ� when selected Ò€œOtherҀ� Tile provider.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25770 β€Ό

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25078 β€Ό

Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24474 β€Ό

Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29455 β€Ό

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25178 β€Ό

Controller may be loaded with malicious firmware which could enable remote code execution

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3657 β€Ό

A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3658 β€Ό

A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234012.

πŸ“– Read

via "National Vulnerability Database".