πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-40735 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BUTTERFLY BUTTON PROJECT - BUTTERFLY BUTTON (Architecture) allows loss of plausible deniability, confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38899 β€Ό

SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.

πŸ“– Read

via "National Vulnerability Database".
⚠ β€œSnakes in airplane mode” – what if your phone says it’s offline but isn’t? ⚠

WYSIWYG is short for "what you see is what you get". Except when it isn't...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-4367 β€Ό

** REJECT ** Duplicate, use CVE-2023-4279 instead.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3366 β€Ό

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2πŸ”₯1
β€Ό CVE-2023-3936 β€Ό

The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39061 β€Ό

Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3667 β€Ό

The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38976 β€Ό

An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38961 β€Ό

Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39106 β€Ό

An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39660 β€Ό

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38836 β€Ό

File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code via the GIF header component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31447 β€Ό

user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3954 β€Ό

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39094 β€Ό

Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code via the username parameter in the student list function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32002 β€Ό

The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x.Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3604 β€Ό

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4456 β€Ό

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38035 β€Ό

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Energy One Investigates Cyberattack πŸ•΄

Energy One is trying to determine the initial point of entry and whether personal information has been compromised.

πŸ“– Read

via "Dark Reading".