๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-42474 โ€ผ

SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44826 โ€ผ

Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-18336 โ€ผ

Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2023-42477 โ€ผ

SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50,ร‚ allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-42475 โ€ผ

The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44848 โ€ผ

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41850 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Morris Bryant, Ruben Sargsyan Outbound Link Manager plugin <=ร‚ 1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44259 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <=ร‚ 2.10.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41854 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Ltd. WpCentral plugin <=ร‚ 1.5.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41853 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <=ร‚ 1.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41858 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <=ร‚ 1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41851 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <=ร‚ 1.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44257 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Hometory Mang Board WP plugin <=ร‚ 1.7.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41852 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailMunch รขโ‚ฌโ€œ Grow your Email List plugin <=ร‚ 3.1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45208 โ€ผ

A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID. Also, network names containing single quotes (in the range of the repeater) can result in a denial of service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41694 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Realbig Team Realbig For WordPress plugin <=ร‚ 1.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5468 โ€ผ

The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5467 โ€ผ

The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2023-41730 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <=ร‚ 1.22.3.31 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41876 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <=ร‚ 1.0.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41697 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Nikunj Soni Easy WP Cleaner plugin <=ร‚ 1.9 versions.

๐Ÿ“– Read

via "National Vulnerability Database".