Tag
#apple
The latest activity from Lazarus Groups, .gov domains scamming people out of "V-Bucks" and more in this week's edition.
GraceHRM version 1.0.3 suffers from a directory traversal vulnerability.
Uvdesk version 1.1.4 suffers from a persistent cross site scripting vulnerability.
This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.
G and G Corporate CMS version 1.0 suffers from a cross site scripting vulnerability.
FreshRSS version 1.11.1 suffers from an html injection vulnerability.
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
Dolibarr version 17.0.1 suffers from a persistent cross site scripting vulnerability.
FoccusWeb CMS version 0.1 suffers from a cross site scripting vulnerability.
Global Multi School Management System Express version 1.0 suffers from a remote SQL injection vulnerability.