π¨ CVE-2018-15645
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2018-15645 - Affects: Odoo 12.0 and earlier (Community an... Β· Issue #63705 Β· odoo/odoo
Security Advisory - CVE-2018-15645 Affects: Odoo 12.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15645 Component: Discuss Credits: Nils Hamerlinck (Trobz) Improper access cont...
π¨ CVE-2019-11783
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
GitHub
[SEC] CVE-2019-11783 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63708 Β· odoo/odoo
Security Advisory - CVE-2019-11783 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11783 Component: Discuss Credits: Nils Hamerlinck (Trobz), Christopher Riis Bu...
π¨ CVE-2019-11785
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.
π@cveNotify
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.
π@cveNotify
GitHub
[SEC] CVE-2019-11785 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63710 Β· odoo/odoo
Security Advisory - CVE-2019-11785 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11785 Component: Discuss Credits: Nils Hamerlinck (Trobz) Improper access cont...
π¨ CVE-2020-35624
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
π@cveNotify
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
π@cveNotify
π¨ CVE-2020-11717
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
π@cveNotify
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
π@cveNotify
Packetstormsecurity
Programi Bilanc Build 007 Release 014 31.01.2020 SQL Injection β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-16166
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
π@cveNotify
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
π@cveNotify
π¨ CVE-2020-8995
Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.
π@cveNotify
Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.
π@cveNotify
seclists.org
Full Disclosure: Programi Bilanc - Build 007 Release 014 31.01.2020 - Broken
encryption with guessable static encryption key [CVEβ¦
encryption with guessable static encryption key [CVEβ¦
π¨ CVE-2020-35491
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
π@cveNotify
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
π@cveNotify
Medium
On Jackson CVEs: Donβt Panic β Here is what you need to know
Addendums (19-May-2020, 28-Sep-2019):
π¨ CVE-2020-35151
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
π@cveNotify
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
π@cveNotify
PHPGurukul
Online Marriage Registration System in PHP | Online Marriage Registration Project
Online Marriage Registration System PHP and MySQL, Download Online Marriage Registration System Project in PHP, live Demo Online Marriage Registration Management project with Source Code on PhpGurukul
π¨ CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
π@cveNotify
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
π@cveNotify
Gist
CVE-2020-27687: Host header injection in Thingsboard prior to version 3.2
CVE-2020-27687: Host header injection in Thingsboard prior to version 3.2 - CVE-2020-27687.md
π¨ CVE-2020-20299
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
π@cveNotify
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
π@cveNotify
GitHub
Y4er/Y4er.com
myblog. Contribute to Y4er/Y4er.com development by creating an account on GitHub.
π¨ CVE-2020-35606
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
π@cveNotify
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
π@cveNotify
Packetstormsecurity
Webmin 1.962 Remote Command Execution β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-25106
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.
π@cveNotify
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.
π@cveNotify
Packetstormsecurity
SUPREMO 4.1.3.2348 Privilege Escalation β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-13547
A type confusion vulnerability exists in the JavaScript engine of Foxit Softwareβs Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
π@cveNotify
A type confusion vulnerability exists in the JavaScript engine of Foxit Softwareβs Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
π@cveNotify
π¨ CVE-2018-7580
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
π@cveNotify
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
π@cveNotify
Ilia Shnaidman
CVE-2018-7580 - Philips Hue Denial of Service
``` [+] Credits: Ilia Shnaidman [+] @0x496c on Twitter [+] https://www.iliashn.com
π¨ CVE-2020-26251
Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case management. In Open Zaak before version 1.3.3 the Cross-Origin-Resource-Sharing policy in Open Zaak is currently wide open - every client is allowed. This allows evil.com to run scripts that perform AJAX calls to known Open Zaak installations, and the browser will not block these. This was intended to only apply to development machines running on localhost/127.0.0.1. Open Zaak 1.3.3 disables CORS by default, while it can be opted-in through environment variables. The vulnerability does not actually seem exploitable because: a) The session cookie has a `Same-Site: Lax` policy which prevents it from being sent along in Cross-Origin requests. b) All pages that give access to (production) data are login-protected c) `Access-Control-Allow-Credentials` is set to `false` d) CSRF checks probably block the remote origin, since they're not explicitly added to the trusted allowlist.
π@cveNotify
Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case management. In Open Zaak before version 1.3.3 the Cross-Origin-Resource-Sharing policy in Open Zaak is currently wide open - every client is allowed. This allows evil.com to run scripts that perform AJAX calls to known Open Zaak installations, and the browser will not block these. This was intended to only apply to development machines running on localhost/127.0.0.1. Open Zaak 1.3.3 disables CORS by default, while it can be opted-in through environment variables. The vulnerability does not actually seem exploitable because: a) The session cookie has a `Same-Site: Lax` policy which prevents it from being sent along in Cross-Origin requests. b) All pages that give access to (production) data are login-protected c) `Access-Control-Allow-Credentials` is set to `false` d) CSRF checks probably block the remote origin, since they're not explicitly added to the trusted allowlist.
π@cveNotify
GitHub
open-zaak/open-zaak
Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case management. - open-zaak/open-zaak
π¨ CVE-2020-27254
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF β all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.
π@cveNotify
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF β all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.
π@cveNotify
us-cert.cisa.gov
Emerson Rosemount X-STREAM | CISA
1. EXECUTIVE SUMMARY
CVSS v3 7.5
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Emerson
Equipment: Rosemount X-STREAM Gas Analyzer
Vulnerability: Improper Authentication
2. RISK EVALUATION
Successful exploitation of this vulnerabilityβ¦
CVSS v3 7.5
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Emerson
Equipment: Rosemount X-STREAM Gas Analyzer
Vulnerability: Improper Authentication
2. RISK EVALUATION
Successful exploitation of this vulnerabilityβ¦
π¨ CVE-2018-15641
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
GitHub
[SEC] CVE-2018-15641 - Affects: Odoo 11.0 through 14.0 (Community a... Β· Issue #63704 Β· odoo/odoo
Security Advisory - CVE-2018-15641 Affects: Odoo 11.0 through 14.0 (Community and Enterprise Editions) CVE ID: CVE-2018-15641 Component: Framework Credits: msg systems ag, Lauri Vakkala (Silverskin...
π¨ CVE-2018-15638
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
GitHub
[SEC] CVE-2018-15638 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63703 Β· odoo/odoo
Security Advisory - CVE-2018-15638 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15638 Component: Discuss Credits: Subash SN and Bharath Kumar (Appsecco), Dipa...
π¨ CVE-2020-24580
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.
π@cveNotify
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.
π@cveNotify
Trustwave
D-Link: Multiple Security Vulnerabilities Leading to RCE
On the 30th of October, D-Link published a support announcement and released a new firmware to patch five vulnerabilities that Harold Zang, Technical Security Specialist at Trustwave, identified on the DSL-2888A router. These security vulnerabilities couldβ¦
π¨ CVE-2020-24579
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
π@cveNotify
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
π@cveNotify
Trustwave
D-Link: Multiple Security Vulnerabilities Leading to RCE
On the 30th of October, D-Link published a support announcement and released a new firmware to patch five vulnerabilities that Harold Zang, Technical Security Specialist at Trustwave, identified on the DSL-2888A router. These security vulnerabilities couldβ¦