๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.1K subscribers
88.4K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-4947 โ€ผ

The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update EAN numbers for orders.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5524 โ€ผ

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5308 โ€ผ

The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' shortcode in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3342 โ€ผ

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the รขโ‚ฌหœzbscrmcsvimpfรขโ‚ฌโ„ข parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do not take any action upon a failed check. These steps then perform a 'file_exists' check on the value of 'zbscrmcsvimpf'. If a phar:// archive is supplied, its contents will be deserialized and an object injected in the execution stream. This allows an unauthenticated attacker to obtain object injection if they are able to upload a phar archive (for instance if the site supports image uploads) and then trick an administrator into performing an action, such as clicking a link.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-4919 โ€ผ

The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up to, and including, 4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permission and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 4.6 and fully patched in version 4.7.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-4924 โ€ผ

The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5615 โ€ผ

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5120 โ€ผ

The Migration, Backup, Staging รขโ‚ฌโ€œ WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-4943 โ€ผ

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5109 โ€ผ

The WP Mailto Links รขโ‚ฌโ€œ Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpml_mailto' shortcode in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 3.1.3 and fully patched in version 3.1.4.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5656 โ€ผ

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended for higher privileged users. This vulnerability is the same as CVE-2023-5533 but was reintroduced in version 4.9.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-3996 โ€ผ

The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44256 โ€ผ

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HTTP request.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44483 โ€ผ

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled.ร‚ Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34045 โ€ผ

VMware Fusion(13.x prior to 13.5)ร‚ contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade.ร‚ A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5618 โ€ผ

The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ›  Faraday 4.6.1 ๐Ÿ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

๐Ÿ“– Read

via "Packet Storm Security".
โ€ผ CVE-2023-3487 โ€ผ

An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46287 โ€ผ

XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46287 โ€ผ

XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ Develop High-Demand Cybersecurity Skills for Just $60 Through 10/23 ๐Ÿฆฟ

Protect your company by learning maximum security practices in this bundle, while it's available at $59.97.

๐Ÿ“– Read

via "Tech Republic".