Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[@builder.io/qwik] @builder.io/qwik vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/20/202301/27/2023

@builder.io/qwik prior to version 0.16.2 is vulnerable to cross-site scripting due to attribute names and the class attribute values not being properly handled.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-0410
https://github.com/builderio/qwi…

[modoboa] Cross-Site Request Forgery in modoboa

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/20/202301/28/2023

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-0406
https://github.com/modoboa/modoboa/commit/7f0573e917227686d2cc127be1364e2908740807
https://huntr.dev/bount…

[jruby-openssl] jruby-openssl gem for JRuby fails to do proper certificate validation

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/20/202301/20/2023

A security problem involving peer certificate verification was found where failed verification silently did nothing, making affected applications vulnerable to attackers. Attackers could lead a client application to believe that a secure connection to …

[modoboa] Modoboa is vulnerable to Cross-Site Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/19/202301/21/2023

Modoboa 2.0.3 and prior is vulnerable to Cross-Site Request Forgery. A patch is available and anticipated to be part of version 2.0.4.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-0398
https://github.com/modoboa/modoboa/commit/8e14ac93669df4f3…

[www.velocidex.com/golang/velociraptor] Velociraptor subject to Path Traversal

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/19/202302/01/2023

Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory traversal in where the collection task could be written. It was possible to provide a client id of “../clients/server” to schedule t…

[actionpack] Open Redirect Vulnerability in Action Pack

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/19/202301/21/2023

There is a vulnerability in Action Controller’s redirect_to. This vulnerability has been assigned the CVE identifier CVE-2023-22797.
Versions Affected: >= 7.0.0 Not affected: < 7.0.0 Fixed Versions: 7.0.4.1
Impact
There is a possible open redirec…

[cookiejar] cookiejar Regular Expression Denial of Service via Cookie.parse function

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/18/202301/24/2023

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function and other aspects of the API, which use an insecure regular expression for parsing cookie values. Applications c…

[mel-spintax] mel-spintax has Inefficient Regular Expression Complexity

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/18/202301/21/2023

A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/spintax.js. The manipulation of the argument text leads to inefficient regular expression complexi…

[shopware/platform] Shopware vulnerable to Improper Input Validation of Clearance sale in cart

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/18/202301/18/2023

Impact
It is possible to put the same line item multiple one in the cart using API, the Cart Validators checked the line item’s individuality and the user was able to skip the clearance sale in cart
Patches
The problem has been fixed with 6.4.18.1
Work…

[sisimai] Sisimai Inefficient Regular Expression Complexity vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 01/18/202301/24/2023

A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function to_plain of the file lib/sisimai/string.rb. The manipulation leads to inefficient regular expression complexity. The explo…

Posts navigation

Previous Posts 1 … 6 7 8 9 10 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close