Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[sanitize] Improper neutralization of `noscript` element content may allow XSS in Sanitize

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/28/202301/28/2023

Impact
Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize >= 5.0.0, < 6.0.1 when Sanitize is configured with a custom allowlist that allows noscript elements. This could result in XSS (cross-site scrip…

[org.glassfish.main.web:web] Path Traversal In Eclipse GlassFish

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/28/2023

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with ‘./’. Successful exploitation could allow an remote unauthenticated attacker to access critical data…

[safeurl-python] safeurl-python contains Server-Side Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202302/03/2023

Description
In SafeURL it is possible to specify a list of domains that should be matched before a request is sent out. The regex used to compare domains did not work as intended.
Impact
The regex used was:
re.match(“(?i)^%s” % domain, value)
This has …

[openmage/magento-lts] DoS vulnerability in MaliciousCode filter

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/28/2023

Impact
Infinite loop in malicious code filter in certain conditions.
Workarounds
None
References

https://github.com/OpenMage/magento-lts/security/advisories/GHSA-3p73-mm7v-4f6m
https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22
https://gith…

[pyload-ng] Cross-site Scripting in pyload-ng

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/27/2023

Cross-site Scripting (XSS) – Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-0488
https://github.com/pyload/pyload/commit/46d75a3087f3237d06530d55998938e2e2bda6bd
https://huntr.dev…

[devise] Devise Gem for Ruby Unauthorized Access Using Remember Me Cookie

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/27/2023

Devise version before 3.5.4 uses cookies to implement a “Remember me” functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the c…

[xaviershay-dm-rails] xaviershay-dm-rails Gem for Ruby exposes sensitive information via the process table

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/2023

xaviershay-dm-rails Gem for Ruby contains a flaw in the execute() function in /datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb. The issue is due to the function exposing sensitive information via the process table. This may allow a local attack…

[yapi-vendor] Cross-site Scripting in yapi-vendor

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202302/02/2023

Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-36686
https://github.com/YMFE/yapi/issues/2190
https://github.com/…

[puppet-facter] Command Injection in puppet-facter

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/27/2023

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25350
https://security.snyk.io/vuln/SNYK-JS-PUPPETFACTER-31…

[serve-lite] Cross-site Scripting (XSS) in serve-lite

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/27/202301/31/2023

All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitizatio…

Posts navigation

Previous Posts 1 2 3 4 5 6 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close