The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Category Archives: Advisories
CVE-2021-24905
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.
Open-Xchange Security Advisory 2022-03-21
Posted by Martin Heiland via Fulldisclosure on Mar 21
Dear subscribers,
we’re sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those
vulnerabilities. Feel free to join our bug bounty programs for OX AppSuite, Dovecot and PowerDNS at HackerOne.
Yours sincerely,
Martin Heiland, Open-Xchange GmbH
Product: OX App Suite
Vendor: OX Software GmbH
Internal reference: OXUIB-1092
Vulnerability type: Cross-Site Scripting (CWE-80)
Vulnerable…
CVE-2020-24772
In Dreamacro 1.1.0, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).
xen-4.16.0-5.fc36
FEDORA-2022-cf87a9b146
Packages in this update:
xen-4.16.0-5.fc36
Update description:
fix build of xen.efi file and package it in /usr/lib/efi
Multiple speculative security issues [XSA-398]
rsh-0.17-94.el8
FEDORA-EPEL-2022-85bd5fc48f
Packages in this update:
rsh-0.17-94.el8
Update description:
Security fix for CVE-2019-7282
rsh-0.17-101.fc36
FEDORA-2022-dd808b5a2c
Packages in this update:
rsh-0.17-101.fc36
Update description:
Security fix for CVE-2019-7282
rsh-0.17-100.fc35
FEDORA-2022-82a6236ac7
Packages in this update:
rsh-0.17-100.fc35
Update description:
Security fix for CVE-2019-7282
rsh-0.17-98.fc34
FEDORA-2022-6748ae617b
Packages in this update:
rsh-0.17-98.fc34
Update description:
Security fix for CVE-2019-7282
[CFP-ESORICS 2022]: 27th European Symposium on Research in Computer Security (ESORICS) 2022
Posted by CFP – ESORICS 2022 on Mar 20
[Apologies for cross-posting]
————————————————————————–
C a l l F o r P a p e r s
27th European Symposium on Research in Computer Security (ESORICS) 2022
26-30 September 2022, Copenhagen, Denmark
URL: https://esorics2022.compute.dtu.dk/#
————————————————————————–
===================
CONFERENCE OUTLINE:
===================
We are looking…