πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-4307 β€Ό

The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4270 β€Ό

The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39069 β€Ό

An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38878 β€Ό

A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaScript in the web browser of a victim by injecting a malicious payload into the 'error' and 'error_description' parameters of 'oauth2.php'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41879 β€Ό

Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.

πŸ“– Read

via "National Vulnerability Database".
🦿 Want a New Job? Explore Opportunities at the 10 Top US Startup Ecosystems 🦿

Written by: Kirstie McDermott

Silicon Valley is just one of a number of key US startup ecosystems fueling startups, all of which drive investment and job creation: check where new opportunities are in the US right now.


πŸ“– Read

via "Tech Republic".
πŸ“’ Zero trust is about more than security – it's the foundation for digital transformation πŸ“’

Businesses are waking up to the potential of leveraging data insights for more than just network security

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-48474 β€Ό

Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37875 β€Ό

Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37881 β€Ό

Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3039 β€Ό

SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26142 β€Ό

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24093 β€Ό

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37878 β€Ό

Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4896 β€Ό

Cyber Control, in its 1.650 version, is affected by a vulnerabilityΓ‚ in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be achieved by sending multiple requests simultaneously on a core.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37879 β€Ό

Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48475 β€Ό

Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the print query created by the request.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ MGM Resorts back online after suspected ransomware attack πŸ“’

The company’s casinos and hotels experienced severe disruption, with financial impacts of the outage expected to be significant

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-40726 β€Ό

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40729 β€Ό

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.

πŸ“– Read

via "National Vulnerability Database".