Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[github.com/Azure/aad-pod-identity] AAD Pod Identity obtaining token with backslash

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/22/202212/22/2022

Impact
What kind of vulnerability is it? Who is impacted?
The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example: /metadata/identity\oauth2…

[smoothie] Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/21/202201/06/2023

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control thes…

[microweber/microweber] Microweber vulnerable to Reflected Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/21/202212/27/2022

Microweber versions 1.3.1 and prior are vulnerable to Reflected Cross-site Scripting (XSS). A patch is available on the 1.4, dev, and laravel-sail branches.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4617
https://github.com/microweber/microw…

[org.apache.zeppelin:zeppelin] Apache Zeppelin Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/21/202212/21/2022

An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users’ browsers. This issue affects Apache Zeppelin before 0.8.2. U…

[github.com/bradleyfalzon/ghinstallation] ghinstallation returns app JWT in error responses

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/20/202212/29/2022

Impact
In ghinstallation v1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging.
https://github.com/bradleyfalzon/ghinstallation/blob/24e56b3fb7669f209134a01eff731d7e2ef72a5c/transpor…

[github.com/cortexproject/cortex] Cortex’s Alertmanager can expose local files content via specially crafted config

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/20/202212/28/2022

Impact
A local file inclusion vulnerability exists in Cortex versions v1.13.0, v1.13.1 and v1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Ale…

[silverstripe/subsites] SilverStripe Subsite weakens file permissions

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/20/202201/04/2023

The subsites module can weaken edit restrictions on some files and allow a malicious user to edit files they do not have edit rights to.
This only affects projects with the subsites module installed. Regression testing should focus on custom file logic…

[whois] FurqanSoftware/node-whois vulnerable to Prototype Pollution

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/20/202212/20/2022

A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). I…

[oils] Oils JS vulnerable to Open Redirect

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/20/202212/28/2022

A vulnerability was found in oils-js. This vulnerability affects unknown code of the file core/Web.js. The manipulation leads to open redirect and the attack can be initiated remotely. The name of the patch is fad8fbae824a7d367dacb90d56cb02c5cb999d42. …

[github.com/usememos/memos] Memos Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 12/19/202212/24/2022

Memos, an open-source, self-hosted memo hub, is vulnerable to stored Cross-site Scripting (XSS) in versions 0.8.3 and prior. A patch is available and anticipated to be part of version 0.9.0.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4609
ht…

Posts navigation

Previous Posts 1 … 23 24 25 26 27 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close