Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Solar monitoring systems exposed: Secure your devices

Categories: Business Tags: solar Tags: monitoring Tags: service Tags: exposed Tags: web Tags: facing Tags: secure Tags: scan Tags: lockdown Tags: update We take a look at reports that 130,000 solar monitoring devices are sitting exposed online. (Read more...) The post Solar monitoring systems exposed: Secure your devices appeared first on Malwarebytes Labs.

Malwarebytes
#vulnerability#web#php
GHSA-wjg8-pxqj-c3c7: Artesãos SEOTools Open Redirect vulnerability

A vulnerability, which was classified as problematic, was found in Artesãos SEOTools up to and including version 0.17.1. This affects the function makeTag of the file OpenGraph.php. The manipulation of the argument value leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component.

GHSA-w745-xjqx-7wp8: Artesãos SEOTools Open Redirect vulnerability

A vulnerability has been found in Artesãos SEOTools up to and including version 0.17.1. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component.

CVE-2023-3528

A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument cat_id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-233252.

CVE-2023-37260: Key exposed in exception message when passing as a string and providing an invalid pass phrase

league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file path will have had that key included in a LogicException message if they did not provide a valid pass phrase for the key where required. This issue has been patched so that the provided key is no longer exposed in the exception message in the scenario outlined above. Users should upgrade to version 8.5.3 to receive the patch. As a workaround, pass the key as a file instead of a string.

CVE-2023-36969: CMS Made Simple v2.2.17 – File Upload Remote Code Execution (RCE) (Authenticated)

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

CVE-2020-21861: Insecure configuration causes getshell · Issue #I182Y4 · 王爷/DuxCMS2.1支持php7.0以上版本 - Gitee.com

File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.

Archon CMS 3.14 Cross Site Scripting

Archon CMS version 3.14 suffers from a cross site scripting vulnerability.

3 Critical RCE Bugs Threaten Industrial Solar Panels, Endangering Grid Systems

Exposed and unpatched solar power monitoring systems have been exploited by both amateurs and professionals, including Mirai botnet hackers.