๐จ CVE-2022-39254
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.
๐@cveNotify
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.
๐@cveNotify
GitHub
When receiving forwarded room keys, we don't check that the forwarder device matches the device we requested from
When matrix-nio before 0.20 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device ...
๐จ CVE-2023-37067
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
๐@cveNotify
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
๐@cveNotify
GitHub
Home
Chamilo is a learning management system focused on ease of use and accessibility - chamilo/chamilo-lms
๐จ CVE-2023-36993
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
๐@cveNotify
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
๐@cveNotify
Bram Does Security
TravianZ Hacked
We will explore how we can get Remote Code Execution (RCE) through cryptographic failures, XSS, etc. in an open source PHP project.
๐จ CVE-2023-36994
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
๐@cveNotify
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
๐@cveNotify
Bram Does Security
TravianZ Hacked
We will explore how we can get Remote Code Execution (RCE) through cryptographic failures, XSS, etc. in an open source PHP project.
๐จ CVE-2023-37700
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6905 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37707
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6904 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37705
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6902 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37704
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6901 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37703
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6907 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37702
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6801 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37701
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6908 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37712
Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.
๐@cveNotify
Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSetIpBind at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
๐@cveNotify
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/saveParentControlInfo at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37710
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
๐@cveNotify
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSetWirelessRepeat at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37706
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6903 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-32040
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify