πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-42656 β€Ό

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scriptingΓ‚ (XSS) vulnerability has been identified in MOVEit Transfer's web interface.Γ‚  An attacker could craft a malicious payload targetingΓ‚ MOVEit Transfer users during the package composition procedure.Γ‚  If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43495 β€Ό

Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43500 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43499 β€Ό

Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43497 β€Ό

In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ FBI, CISA Issue Joint Warning on 'Snatch' Ransomware-as-a-Service πŸ•΄

The group's use of malware that forces Windows computers to reboot into Safe Mode before encrypting files is noteworthy, advisory says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Fake WinRAR PoC Exploit Conceals VenomRAT Malware πŸ•΄

A supposed exploit for a notable RCE vulnerability in the popular Windows file-archiving utility delivers a big sting for unwitting researchers and cybercriminals.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20594 β€Ό

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43377 β€Ό

A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-43371 β€Ό

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43373 β€Ό

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43376 β€Ό

A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20597 β€Ό

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40368 β€Ό

IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40618 β€Ό

A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39041 β€Ό

An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43375 β€Ό

Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.

πŸ“– Read

via "National Vulnerability Database".