πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-36133 β€Ό

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38991 β€Ό

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4142 β€Ό

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code on the server. The author resolved this vulnerability by removing the ability for authors and editors to import files, please note that this means remote code execution is still possible for site administrators, use the plugin with caution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36135 β€Ό

User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0525 β€Ό

Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21 model versions 01.49.000 and prior, GT Designer3 Version1 (GOT2000) versions 1.295H and prior and GT SoftGOT2000 versions 1.295H and prior allows a remote unauthenticated attacker to obtain plaintext passwords by sniffing packets containing encrypted passwords and decrypting the encrypted passwords, in the case of transferring data with GT Designer3 Version1(GOT2000) and GOT2000 Series or GOT SIMPLE Series with the Data Transfer Security function enabled, or in the case of transferring data by the SoftGOT-GOT link function with GT SoftGOT2000 and GOT2000 series with the Data Transfer Security function enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38708 β€Ό

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite.The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36141 β€Ό

User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36138 β€Ό

PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36132 β€Ό

PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4140 β€Ό

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator previously grants access in the plugin settings, to modify their user role by supplying the 'wp_capabilities->cus1' parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30146 β€Ό

Assmann Digitus Plug&View IP Camera family allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-36131 β€Ό

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36158 β€Ό

Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30297 β€Ό

An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4139 β€Ό

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33665 β€Ό

ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36134 β€Ό

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39379 β€Ό

Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google, Microsoft Take Refuge in Rust Language's Better Security πŸ•΄

More tech giants turn to the Rust programming language for its built-in memory safety and other security features.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ How To Deal With the Vagueness in New Cyber Regulations πŸ•΄

Recent regulations for privacy, AI, and breaches tend to be overly broad, suggesting that the rulemakers lack tech acumen.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Teach a Man to Phish and He’s Set for Life β™ŸοΈ

One frustrating aspect of email phishing is the frequency with which scammers fall back on tried-and-true methods that really have no business working these days. Like attaching a phishing email to a traditional, clean email message, or leveraging link redirects on LinkedIn, or abusing an encoding method that makes it easy to disguise booby-trapped Microsoft Windows files as relatively harmless documents.

πŸ“– Read

via "Krebs on Security".