Tag
#apple
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a crafted script to the getModuleTranslation function.
Yes, your iPhone automatically turns on NameDrop with the latest software update. But you shouldn’t really be worried about it—regardless of what the police are saying.
By Deeba Ahmed Amazon and eBay have been declared the highest data-collecting platforms among all the Android shopping apps researchers examined. This is a post from HackRead.com Read the original post: Study Finds Amazon, eBay and Afterpay as Top Android User Data Collectors
What you look for online is up to you—just make sure no one else is taking a peek.
CSZ CMS version 1.3.0 suffers from a remote shell upload vulnerability.
Nothing's new message app Chats has been pulled from Google Play after harsh criticism about security issues.
Browser push notifications are becoming a problem on macOS. Learn how to remove them.
Compromised websites are being used to redirect to fake browser updates and deliver malware onto Mac users.
Jorani Leave Management System version 1.0.2 suffers from a host header injection vulnerability.