βΌ CVE-2023-4277 βΌ
π Read
via "National Vulnerability Database".
The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4276 βΌ
π Read
via "National Vulnerability Database".
The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31209 βΌ
π Read
via "National Vulnerability Database".
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.π Read
via "National Vulnerability Database".
π’ ICO threatens enforcement action against websites with 'harmful' cookie banners π’
π Read
via "ITPro".
Cookie banners and defaults among practices coming under greater scrutiny π Read
via "ITPro".
ITPro
ICO threatens enforcement action against websites with 'harmful' cookie banners
Cookie banners and defaults among practices coming under greater scrutiny
βΌ CVE-2023-24009 βΌ
π Read
via "National Vulnerability Database".
Auth. (subscriber+) Reflected Cross-site Scripting (XSS) vulnerability in Wpazure Themes Upfrontwp theme <=Γ 1.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37988 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <=Γ 2.5.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23871 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Webdzier Button plugin <=Γ 1.1.23 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23798 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <=Γ 1.1.9.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23826 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arsham Mirshah Add Posts to Pages plugin <=Γ 1.4.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24389 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <=Γ 2.2.3 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27861 βΌ
π Read
via "National Vulnerability Database".
Unauth. Open Redirect vulnerability in Arscode Ninja Popups plugin <=Γ 4.7.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44629 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <=Γ 2.0.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26311 βΌ
π Read
via "National Vulnerability Database".
A remote code execution vulnerability in the webview component of OPPO Store app.π Read
via "National Vulnerability Database".
β Microsoft Patch Tuesday: 74 CVEs plus 2 βExploit Detectedβ advisories β
π Read
via "Naked Security".
74 CVEs, and two "Exploitation Detected" advisories, which are nearly but not quite the same as 0-days. Also, two potential Teams treacheries that you really want to fix. π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π΄ DAY 2! Dark Reading News Desk: Live at Black Hat USA 2023 π΄
π Read
via "Dark Reading".
Dark Reading News Desk returns for a second day of interviews from Black Hat USA 2023. The livestream will start at 10 a.m. PT.π Read
via "Dark Reading".
Dark Reading
Dark Reading News Desk at Black Hat USA 2023
Dark Reading News Desk was on air for two whole days during Black Hat USA 2023.
β S3 Ep147: What if you type in your password during a meeting? β
π Read
via "Naked Security".
Latest episode - listen now! (Full transcript inside.)π Read
via "Naked Security".
Sophos News
S3 Ep147: What if you type in your password during a meeting?
Latest episode β listen now! (Full transcript inside.)
βΌ CVE-2023-30481 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <=Γ 3.2.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24391 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Spider Teams ApplyOnline plugin <=Γ 2.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37983 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NoΓΒ«l Jackson Art Direction plugin <=Γ 0.2.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4283 βΌ
π Read
via "National Vulnerability Database".
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37069 βΌ
π Read
via "National Vulnerability Database".
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.π Read
via "National Vulnerability Database".