πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-45269 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <=Γ‚ 2.0.23 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40682 β€Ό

IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45270 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <=Γ‚ 2.9.9.4.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5409 β€Ό

HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45276 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <=Γ‚ 1.3 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Security Pros Warn that EU's Vulnerability Disclosure Rule is Risky πŸ•΄

The European Union's Cyber Resilience Act's requirement to disclose vulnerabilities within 24 hours of exploitation could potentially expose organizations to attacks from adversaries or government surveillance.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Feds: Beware AvosLocker Ransomware Attacks on Critical Infrastructure πŸ•΄

CISA and FBI warn the RaaS provider's affiliates are striking critical industries, with more attacks expected to come from additional ransomware groups in the months ahead.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How MOVEit Is Likely to Shift Cyber Insurance Calculus πŸ•΄

Progress Software plans to collect millions in cyber insurance policy payouts after the MOVEit breaches, which will make getting coverage more expensive and harder to get for everyone else, experts say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-4257 β€Ό

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45853 β€Ό

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30148 β€Ό

Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45674 β€Ό

Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to Information Disclosure. This issue has been patched in version 15.8.4. Users are advised to upgrade. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30154 β€Ό

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45852 β€Ό

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45348 β€Ό

Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default.It is recommended to upgrade to a version that is not affected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5578 β€Ό

A vulnerability was found in PortÑbilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input ");'> <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-242143. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42792 β€Ό

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't.Users of Apache Airflow are strongly advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42663 β€Ό

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42780 β€Ό

Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of import errors for those DAGs with import errors.Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33161 β€Ό

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5582 β€Ό

A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown processing of the component Personal Profile Page. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-242147.

πŸ“– Read

via "National Vulnerability Database".