Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

Sielco Radio Link 2.06 Cross-Site Request Forgery (Add Admin)

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Zero Science Lab
#xss#csrf#vulnerability#web
Microsoft Patches 'Dangerous' RCE Flaw in Azure Cloud Service

The vulnerability would have allowed an unauthenticated attacker to execute code on a container hosted on one of the platform's nodes.

Vulnerability Enabled Bing.com Takeover, Search Result Manipulation

By Habiba Rashid Cybersecurity researchers at Wiz reported the vulnerability to Microsoft and dubbed the attack "BingBang". This is a post from HackRead.com Read the original post: Vulnerability Enabled Bing.com Takeover, Search Result Manipulation

Eve-ng 5.0.1-13 Cross Site Scripting

Eve-ng version 5.0.1-13 suffers from a cross site scripting vulnerability.

WordPress WPForms 1.7.8 Cross Site Scripting

WordPress WPForms plugin version 1.7.8 suffers from a cross site scripting vulnerability.

myBB forums 1.8.26 Cross Site Scripting

myBB forums version 1.8.26 suffers from a persistent cross site scripting vulnerability.

Uniview NVR301-04S2-P4 Cross Site Scripting

Uniview NVR301-04S2-P4 suffers from a cross site scripting vulnerability.

Researchers Detail Severe "Super FabriXss" Vulnerability in Microsoft Azure SFX

Details have emerged about a now-patched vulnerability in Azure Service Fabric Explorer (SFX) that could lead to unauthenticated remote code execution. Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022. "The Super FabriXss vulnerability

CVE-2023-28733: Changelog - AcyMailing

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

CVE-2023-25040: WordPress Shortcodes Ultimate plugin <= 5.12.6 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions.