Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Patient Record Management System 1.0 Authentication Bypass

Patient Record Management System version 1.0 suffers from an authentication bypass vulnerability during account recovery.

Packet Storm
#sql#vulnerability#linux#apache#git#php#auth
Inout Multi-Vendor Shopping Cart 3.2.3 SQL Injection

Inout Multi-Vendor Shopping Cart version 3.2.3 suffers from a remote SQL injection vulnerability.

Inout Multi-Vendor Shopping Cart 3.2.3 Cross Site Scripting

Inout Multi-Vendor Shopping Cart version 3.2.3 suffers from a cross site scripting vulnerability.

CVE-2022-43959: Security

Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.

Gamaredon Group Launches Cyberattacks Against Ukraine Using Telegram

The Russian state-sponsored cyber espionage group known as Gamaredon has continued its digital onslaught against Ukraine, with recent attacks leveraging the popular messaging app Telegram to strike military and law enforcement sectors in the country. "The Gamaredon group's network infrastructure relies on multi-stage Telegram accounts for victim profiling and confirmation of geographic location,

CVE-2022-46890: NexusPHP - SureCloud Security Review Identifies Authenticated and Unauthenticated Vulnerabilities

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

CVE-2022-47745: GitHub - l3s10n/ZenTaoPMS_SqlInjection

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

CVE-2022-47740: PoCs/seltmann_gmbh_cms.md at main · blockomat2100/PoCs

Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.

SLIMS 9.5.2 Cross Site Scripting

SLIMS version 9.5.2 suffers from a cross site scripting vulnerability.

CVE-2023-0403: SWP_Options_Page.php in social-warfare/trunk/lib/options – WordPress Plugin Repository

The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers to delete post meta information and reset network access tokens, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.