๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-39058 โ€ผ

An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39446 โ€ผ

** UNSUPPPORTED WHEN ASSIGNED ** Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39452 โ€ผ

** UNSUPPPORTED WHEN ASSIGNED ** The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
๐Ÿฆฟ White Hat Hackers Discover Microsoft Leak of 38TB of Internal Data Via Azure Storage ๐Ÿฆฟ

The Microsoft leak, which stemmed from AI researchers sharing open-source training data on GitHub, has been mitigated.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2023-42454 โ€ผ

SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is the current working directory (the default), and with their database exposed publicly, is vulnerable to an attacker retrieving database connection information from SQLPage and using it to connect to their database directly. Version 0.11.0 fixes this issue. Some workarounds are available. Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. Using a different web root (that is not a parent of the SQLPage configuration directory) fixes the issue. One should also avoid exposing one's database publicly.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-37611 โ€ผ

Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39056 โ€ผ

An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41443 โ€ผ

SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-42446 โ€ผ

Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39049 โ€ผ

An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2023-39046 โ€ผ

An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41599 โ€ผ

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40788 โ€ผ

SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5060 โ€ผ

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-28357 โ€ผ

NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-42399 โ€ผ

Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-26837 โ€ผ

SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 'ShroudedSnooper' Backdoors Use Ultra-Stealth in Mideast Telecom Attacks ๐Ÿ•ด

The threat cluster hasn't been seen before, but its custom Windows server backdoors have researchers intrigued thanks to their extremely effective stealth mechanisms.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1
โ€ผ CVE-2023-0773 โ€ผ

The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2567 โ€ผ

A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way.

๐Ÿ“– Read

via "National Vulnerability Database".