๐จ CVE-2021-20876
Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's server via unspecified vectors.
๐@cveNotify
Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's server via unspecified vectors.
๐@cveNotify
๐จ CVE-2021-20875
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.
๐@cveNotify
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.
๐@cveNotify
๐จ CVE-2021-20874
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.
๐@cveNotify
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.
๐@cveNotify
๐จ CVE-2021-20827
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the attacker may access the PLC Web server and hijack the PLC, and manipulation of the PLC output and/or suspension of the PLC may be conducted.
๐@cveNotify
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the attacker may access the PLC Web server and hijack the PLC, and manipulation of the PLC output and/or suspension of the PLC may be conducted.
๐@cveNotify
๐จ CVE-2021-20826
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.
๐@cveNotify
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.
๐@cveNotify
๐จ CVE-2021-23772
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12.
The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
๐@cveNotify
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12.
The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
๐@cveNotify
Snyk Vulnerability Database
Arbitrary File Write in github.com/kataras/iris | CVE-2021-23772 | Snyk
Fix high severity Arbitrary File Write vulnerability affecting github.com/kataras/iris package, versions *
โ ๏ธโน๏ธโ ๏ธ Hi everybody! To continue providing posts and keeping this channel alive, we accept advertising on the channel.
For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธ
For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธ
CVE Notify pinned ยซโ ๏ธโน๏ธโ ๏ธ Hi everybody! To continue providing posts and keeping this channel alive, we accept advertising on the channel. For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธยป
๐จ CVE-2021-4072
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
๐@cveNotify
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
๐@cveNotify
GitHub
fix(reported_content): sanitize report URLs ยท Elgg/Elgg@c30b17b
A social networking engine in PHP/MySQL. Contribute to Elgg/Elgg development by creating an account on GitHub.
๐จ CVE-2021-30890
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
๐@cveNotify
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
๐@cveNotify
Apple Support
About the security content of tvOS 15.1
This document describes the security content of tvOS 15.1.
๐จ CVE-2021-30887
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
๐@cveNotify
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
๐@cveNotify
Apple Support
About the security content of tvOS 15.1
This document describes the security content of tvOS 15.1.
โ ๏ธโน๏ธโ ๏ธ Hi everybody! To continue providing posts and keeping this channel alive, we accept advertising on the channel.
For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธ
For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธ
CVE Notify pinned ยซโ ๏ธโน๏ธโ ๏ธ Hi everybody! To continue providing posts and keeping this channel alive, we accept advertising on the channel. For advertising plans contact @SirMalware โ ๏ธโน๏ธโ ๏ธยป
๐จ CVE-2021-3977
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
๐@cveNotify
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
๐@cveNotify
GitHub
Fixes for client password reset ยท invoiceninja/invoiceninja@1186eaa
Invoices, Expenses and Tasks built with Laravel and Flutter - Fixes for client password reset ยท invoiceninja/invoiceninja@1186eaa
๐จ CVE-2021-23574
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions.
This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
๐@cveNotify
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions.
This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
๐@cveNotify
Snyk Vulnerability Database
Prototype Pollution in org.webjars.bower:js-data | CVE-2021-23574 | Snyk
Fix high severity Prototype Pollution vulnerability affecting org.webjars.bower:js-data package, versions [0,]
๐จ CVE-2021-23490
The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.
๐@cveNotify
The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Regular Expression Denial of Service (ReDoS) in parse-link-header | CVE-2021-23490 | Snyk
High severity (7.5) Regular Expression Denial of Service (ReDoS) in parse-link-header | CVE-2021-23490
๐จ CVE-2021-3027
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
๐@cveNotify
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
๐@cveNotify
๐จ CVE-2021-45480
An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.
๐@cveNotify
An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.
๐@cveNotify
๐จ CVE-2021-45483
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.
๐@cveNotify
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.
๐@cveNotify
GitHub
security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories
A repository for archiving my vulnerability discoveries. - security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories
๐จ CVE-2021-45482
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.
๐@cveNotify
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.
๐@cveNotify
GitHub
security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories
A repository for archiving my vulnerability discoveries. - security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories
๐จ CVE-2021-45481
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.
๐@cveNotify
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.
๐@cveNotify
GitHub
security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories
A repository for archiving my vulnerability discoveries. - security_advisories/webkitgtk-2.32.3 at master ยท ChijinZ/security_advisories