Category Archives: Advisories

[KIS-2024-05] XenForo <= 2.2.15 (Widget::actionSave) Cross-Site Request Forgery Vulnerability

Read Time:13 Second

Posted by Egidio Romano on Jul 16

——————————————————————————-
XenForo <= 2.2.15 (Widget::actionSave) Cross-Site Request Forgery Vulnerability
——————————————————————————-

[-] Software Link:

https://xenforo.com

[-] Affected Versions:

Version 2.2.15 and prior versions.

[-] Vulnerability Description:

The XFAdminControllerWidget::actionSave() method, defined into the…

Read More

USN-6899-1: GTK vulnerability

Read Time:12 Second

It was discovered that GTK would attempt to load modules from the current
directory, contrary to expectations. If users started GTK applications from
shared directories, a local attacker could use this issue to execute
arbitrary code, and possibly escalate privileges.

Read More