βΌ CVE-2023-3887 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235249 was assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3883 βΌ
π Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/add-category.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235245 was assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3890 βΌ
π Read
via "National Vulnerability Database".
A vulnerability classified as problematic has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit-accepted-appointment.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235251.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3888 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235250 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35088 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.Γ In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.[1] https://github.com/apache/inlong/pull/8198π Read
via "National Vulnerability Database".
βΌ CVE-2023-3897 βΌ
π Read
via "National Vulnerability Database".
User enumeration in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message.This issue affects SureMDM On-premise: 6.31 and below versionΓ π Read
via "National Vulnerability Database".
βΌ CVE-2023-3885 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/edit_category.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235247.π Read
via "National Vulnerability Database".
π¦Ώ How to Create a Custom Security & Threat Dashboard in Power BI π¦Ώ
π Read
via "Tech Republic".
Want a custom security dashboard to bring together data from multiple places? Microsoft Power BI can do that and help you spot what's changing.π Read
via "Tech Republic".
TechRepublic
How to Create a Custom Security & Threat Dashboard in Power BI
Learn to create custom security and threat dashboards for an overview of multiple data sources in Power BI with this guide.
π1
π’ Apple patches zero day linked to spyware campaign π’
π Read
via "ITPro".
Kaspersky researchers were the first to report a zero day used in a sophisticated attack chain π Read
via "ITPro".
ITPro
Apple patches zero day linked to spyware campaign
Kaspersky researchers were the first to report a zero day used in a sophisticated attack chain
βΌ CVE-2023-2850 βΌ
π Read
via "National Vulnerability Database".
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23833 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <=Γ 1.7.10 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3486 βΌ
π Read
via "National Vulnerability Database".
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG hostΓ’β¬β’s file storage. This could exhaust system resources and prevent the service from operating as expected.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3637 βΌ
π Read
via "National Vulnerability Database".
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2023-33925 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PluginForage WooCommerce Product Categories Selection Widget plugin <=Γ 2.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35043 βΌ
π Read
via "National Vulnerability Database".
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <=Γ 1.1 versions.π Read
via "National Vulnerability Database".
π jSQL Injection 0.90 π
π Read
via "Packet Storm Security".
jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the source code release.π Read
via "Packet Storm Security".
Packetstormsecurity
jSQL Injection 0.90 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2023-39174 βΌ
π Read
via "National Vulnerability Database".
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackersπ Read
via "National Vulnerability Database".
βΌ CVE-2023-34017 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <=Γ 2.6.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36502 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <=Γ 1.3.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34093 βΌ
π Read
via "National Vulnerability Database".
Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attribute of a Content-Type public without knowing it. The vulnerability only affects the handling of content types by Strapi, not the actual content types themselves. Users can use plugins or modify their own content types without realizing that the `privateAttributes` getter is being removed, which can result in any attribute becoming public. This can lead to sensitive information being exposed or the entire system being taken control of by an attacker(having access to password hashes). Anyone can be impacted, depending on how people are using/extending content-types. If the users are mutating the content-type, they will not be affected. Version 4.10.8 contains a patch for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36501 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <=Γ 9.0.2 versions.π Read
via "National Vulnerability Database".