🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-48589 ‼

A SQL injection vulnerability exists in the “reporting job editor� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-39002 ‼

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense before 23.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48593 ‼

A SQL injection vulnerability exists in the “topology data service� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48595 ‼

A SQL injection vulnerability exists in the “ticket template watchers� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48591 ‼

A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48580 ‼

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48598 ‼

A SQL injection vulnerability exists in the “reporter events type date� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-38999 ‼

A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense before 23.7 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-39004 ‼

Insecure permissions in the configuration directory (/conf/) of OPNsense before 23.7 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48599 ‼

A SQL injection vulnerability exists in the “reporter events type� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48592 ‼

A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report� feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-39007 ‼

/ui/cron/item/open in the Cron component of OPNsense before 23.7 allows XSS.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-38998 ‼

An open redirect in the Login page of OPNsense before 23.7 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

📖 Read

via "National Vulnerability Database".
🕴 It's Time for Cybersecurity to Talk About Climate Change 🕴

From e-waste to conference swag to addressing data center energy consumption, cybersecurity stakeholders need a whole-industry approach to being part of the solution and reducing the risk of climate change.

📖 Read

via "Dark Reading".
🕴 New LLM Tool Seeks and Remediates Vulnerabilities 🕴

Vicarius launched vuln_GPT, which it says will generate and execute scripts to ameliorate flaws such as the TETRA backdoor.

📖 Read

via "Dark Reading".
🕴 Researchers Detail Vuln That Allowed for Windows Defender Update Process Hijack 🕴

Newly patched flaw allowed attackers to sneak malware past Defender, delete benign files, and inflict mayhem on target systems.

📖 Read

via "Dark Reading".
🕴 Black Hat Opens With Call to Steer AI from Predictions to Policy 🕴

Without cybersecurity guardrails now, AI will be harder to harness in the future.

📖 Read

via "Dark Reading".
🕴 Blockchain Signing Bug Cracks Open Crypto Investors' Wallets Worldwide 🕴

Bugs in popular digital signature schemes designed to protect crypto investors allow attackers to steal private keys gain full access to digital wallets.

📖 Read

via "Dark Reading".
🕴 DARPA Launches Two-Year Contest to Build AI Tools to Fix Vulnerabilities 🕴

A challenge will be offered to teams to build tools using AI in order to solve open source's vulnerability challenges.

📖 Read

via "Dark Reading".