Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2012-10007: fixed vulnerability · madgicweb/buddystream@7d5b9a8

A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.8 is able to address this issue. The name of the patch is 7d5b9a89a27711aad76fd55ab4cc4185b545a1d0. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221479.

CVE
#xss#vulnerability#web#google#php

@@ -2,8 +2,8 @@ Contributors: Blackphantom Tags: Buddypress, Twitter, Facebook, Flickr, Tweetstream, Facestream, Google+, Soundcloud, Rss, Last.fm, Vimeo, LinkedIn, Buddystream, Apollo Requires at least: WP 2.9.1, BuddyPress 1.2.3 Tested up to: WP 3.4.1, BuddyPress 1.6.1 Stable tag: 2.6.2 Tested up to: WP 3.4.2, BuddyPress 1.6.1 Stable tag: 2.6.3
== Released under the GPL license == http://www.opensource.org/licenses/gpl-license.php @@ -39,6 +39,9 @@ For support and other feature request, please contact us on our website.
== ChangeLog ==
= 2.6.3 = * Fixed vulnerability in the ShareBox
= 2.6.2 = * Improved check for sending out to networks (now no longer conflicts with plugins like activity hashtags) * Small CSS fix for BuddyPress 1.6 support.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907