Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-3673: [Task]: Improve Admin translation and application logger sorting (#15… · pimcore/pimcore@a06ce0a

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.

CVE
#sql#js#git
BreachForums’ Pompompurin Pleads Guilty to Holding Child Abuse Content

By Waqas According to court documents, devices owned by Pompompurin contained 600 explicit images of child abuse, which led him to plead guilty in court. This is a post from HackRead.com Read the original post: BreachForums’ Pompompurin Pleads Guilty to Holding Child Abuse Content

CVE-2023-3672: XSS mitigation · PlaidWeb/webmention.js@3551b66

Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.

TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that's focused on Azure and Google Cloud Platform (GCP) services, marking the adversary's expansion in targeting beyond Amazon Web Services (AWS). The findings come from SentinelOne and Permiso, which said the "campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew,"

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

A new malware strain has been found covertly targeting small office/home office (SOHO) routers for more than two years, infiltrating over 70,000 devices and creating a botnet with 40,000 nodes spanning 20 countries. Lumen Black Lotus Labs has dubbed the malware AVrecon, making it the third such strain to focus on SOHO routers after ZuoRAT and HiatusRAT over the past year. "This makes AVrecon one

GHSA-7gj7-224w-vpr3: Thymeleaf allows sandbox bypass via crafted HTML

Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.

CVE-2023-38286: GitHub - p1n93r/SpringBootAdmin-thymeleaf-SSTI: SpringBootAdmin-thymeleaf-SSTI which can cause RCE

Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.

GHSA-c6v5-pf66-xfq8: Froxlor vulnerable to Improper Encoding or Escaping of Output

Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

CVE-2023-3668: huntr – Security Bounties for any GitHub repository

Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.