π¨ CVE-2019-18577
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.
π@cveNotify
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.
π@cveNotify
π¨ CVE-2019-18578
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious HTML or JavaScript code in application fields. When victim users access the injected page through their browsers, the malicious code may be executed by the web browser in the context of the vulnerable web application.
π@cveNotify
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious HTML or JavaScript code in application fields. When victim users access the injected page through their browsers, the malicious code may be executed by the web browser in the context of the vulnerable web application.
π@cveNotify
π¨ CVE-2019-3769
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
π@cveNotify
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
π@cveNotify
π¨ CVE-2019-3770
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
π@cveNotify
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
π@cveNotify
π¨ CVE-2020-10562
An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
π@cveNotify
An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
π@cveNotify
GitHub
sous-version 3.4.1c : mise Γ jour de sΓ©curitΓ© Β· JeromeDevome/GRR@2c6edac
GRR Officiel - Copyright Team DEVOME. Contribute to JeromeDevome/GRR development by creating an account on GitHub.
π¨ CVE-2020-10563
An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
π@cveNotify
An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
π@cveNotify
GitHub
sous-version 3.4.1c : mise Γ jour de sΓ©curitΓ© Β· JeromeDevome/GRR@2c6edac
GRR Officiel - Copyright Team DEVOME. Contribute to JeromeDevome/GRR development by creating an account on GitHub.
π¨ CVE-2020-5257
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the `direction` parameter and bypass ActiveRecord SQL protections.
Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication.
This is patched in wersion 0.13.0.
π@cveNotify
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the `direction` parameter and bypass ActiveRecord SQL protections.
Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication.
This is patched in wersion 0.13.0.
π@cveNotify
GitHub
Merge pull request from GHSA-2p5p-m353-833w Β· thoughtbot/administrate@3ab838b
Previously, order parameters were passed directly through to the query.
This meant that passing in `foo` via a URL string would try and sort by
`foo`.
This meant that passing in `foo` via a URL string would try and sort by
`foo`.
π¨ CVE-2020-5240
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password. The problem has been patched in version 1.4.1.
π@cveNotify
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password. The problem has been patched in version 1.4.1.
π@cveNotify
GitHub
Prevent unauthorized users managing others' device Β· labd/wagtail-2fa@ac23550
This adds a permissions check on the device list and delete views. When
a user has the 'change_user' permission, they are allowed to view
and delete other users' 2FA devices...
a user has the 'change_user' permission, they are allowed to view
and delete other users' 2FA devices...
π¨ CVE-2020-10564
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
π@cveNotify
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
π@cveNotify
GitHub
CVE/WP-File-Upload_disclosure_report at master Β· beerpwn/CVE
CVE, reports, research. Contribute to beerpwn/CVE development by creating an account on GitHub.
π¨ CVE-2020-10565
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS.
π@cveNotify
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS.
π@cveNotify
π¨ CVE-2020-10566
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.
π@cveNotify
grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.
π@cveNotify
π¨ CVE-2020-10567
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)
π@cveNotify
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)
π@cveNotify
GitHub
remote code execution vulnerability in ajax_calls.php in save_img action because of no validation on extension name. Β· Issue #600β¦
after taking another look at your application i noticed in the ajax_calls.php file in the "save_img" action that the "name" parameter doesn't validate the extension of the f...
π¨ CVE-2020-10568
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
π@cveNotify
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
π@cveNotify
Medium
Sitepress Multilingual CMS WPlugin (WPML) < 4.3.7-b.2
A vulnerability in the Sitepress Multilingual CMS WordPress plugin (WPML) leads to remote code execution by opening a link
π¨ CVE-2020-10571
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.
π@cveNotify
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.
π@cveNotify
GitHub
v1.9.4 by kyamagu Β· Pull Request #198 Β· psd-tools/psd-tools
[compression] Security fix, affected versions are 1.8.37 - 1.9.3.
π¨ CVE-2020-10573
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.
π@cveNotify
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.
π@cveNotify
GitHub
Fixed double unlock when listing private rooms in AudioBridge by lminiero Β· Pull Request #1988 Β· meetecho/janus-gateway
Ref: CVE-2020-10573
We've been notified about a double unlock that could happen when sending a "list" request to a AudioBridge instance hosting private rooms. Indeed, whil...
We've been notified about a double unlock that could happen when sending a "list" request to a AudioBridge instance hosting private rooms. Indeed, whil...
π¨ CVE-2020-10574
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
π@cveNotify
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
π@cveNotify
GitHub
Fixed typo in querylogger_parameters (copy/paste error) by lminiero Β· Pull Request #1989 Β· meetecho/janus-gateway
Ref: CVE-2020-10574
We've been notified about a typo in the JSON validation of the "query_logger" Admin API request, that could lead to trying to use a string that doesn&a...
We've been notified about a typo in the JSON validation of the "query_logger" Admin API request, that could lead to trying to use a string that doesn&a...
π¨ CVE-2020-10575
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.
π@cveNotify
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.
π@cveNotify
GitHub
Several fixes to session management in VideoCall plugin by lminiero Β· Pull Request #1994 Β· meetecho/janus-gateway
Ref: CVE-2020-10575
We've been notified about some issues in the VideoCall plugin, specifically some race conditions that could lead to crashes in Janus. After some investigations, this see...
We've been notified about some issues in the VideoCall plugin, specifically some race conditions that could lead to crashes in Janus. After some investigations, this see...
π¨ CVE-2020-10576
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.
π@cveNotify
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.
π@cveNotify
GitHub
Fixes to leaks and race conditions in VoiceMail plugin by lminiero Β· Pull Request #1993 Β· meetecho/janus-gateway
Ref: CVE-2020-10576
We've been notified about some issues with the VoiceMail plugin, which in part didn't surprise me as it hasn't been touched much since it was first creat...
We've been notified about some issues with the VoiceMail plugin, which in part didn't surprise me as it hasn't been touched much since it was first creat...
π¨ CVE-2020-10577
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
π@cveNotify
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
π@cveNotify
GitHub
Fix rare race condition when claiming sessions by lminiero Β· Pull Request #1990 Β· meetecho/janus-gateway
Ref: CVE-2020-10577
We've been notified about a rare race condition that can occur when claiming sessions, specifically when a "claim" request for a session happens at the...
We've been notified about a rare race condition that can occur when claiming sessions, specifically when a "claim" request for a session happens at the...
π¨ CVE-2020-10578
An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
π@cveNotify
An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
π@cveNotify
π¨ CVE-2020-10587
antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.
π@cveNotify
antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.
π@cveNotify