🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-26149

Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:**If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.

📖 Read

via "National Vulnerability Database".
CVE-2023-5233

The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

📖 Read

via "National Vulnerability Database".
📢 Life after the cookie has crumbled 📢

With cookies expected to be phased out in the next few years, businesses will be seeking new avenues to gain first-party data

📖 Read

via "ITPro".
📢 ICO warns against Excel spreadsheets to curb public sector data breaches 📢

The ICO's advisory follows a spate of data protection blunders at UK police forces in recent months

📖 Read

via "ITPro".
🕴 Supply Chain Attackers Escalate With GitHub Dependabot Impersonation 🕴

Armed with stolen developer passcodes, attackers have checked in changes to repositories under the automation feature's name in an attempt to escape notice.

📖 Read

via "Dark Reading".
🕴 4 Legal Surprises You May Encounter After a Cybersecurity Incident 🕴

Many organizations are not prepared to respond to all the constituencies that come knocking after a breach or ransomware incident.

📖 Read

via "Dark Reading".
CVE-2023-43869

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 Function.

📖 Read

via "National Vulnerability Database".
CVE-2023-43861

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.

📖 Read

via "National Vulnerability Database".
CVE-2023-43860

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.

📖 Read

via "National Vulnerability Database".
CVE-2023-43876

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

📖 Read

via "National Vulnerability Database".
CVE-2023-43878

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.

📖 Read

via "National Vulnerability Database".
CVE-2022-47187

There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can be injected into the uploaded file.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2023-43868

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

📖 Read

via "National Vulnerability Database".
CVE-2023-40307

An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of data.

📖 Read

via "National Vulnerability Database".
CVE-2023-43873

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

📖 Read

via "National Vulnerability Database".
CVE-2023-43871

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

📖 Read

via "National Vulnerability Database".
CVE-2023-43866

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

📖 Read

via "National Vulnerability Database".
CVE-2023-43872

A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

📖 Read

via "National Vulnerability Database".
CVE-2023-43874

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.

📖 Read

via "National Vulnerability Database".
CVE-2023-5215

A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly.

📖 Read

via "National Vulnerability Database".
CVE-2023-43879

Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.

📖 Read

via "National Vulnerability Database".