Security
Headlines
HeadlinesLatestCVEs

Tag

#php

SugarCRM 12.2.0 Shell Upload

SugarCRM versions 12.2.0 and below suffers from a multiple step remote shell upload vulnerability.

Packet Storm
#vulnerability#php
GEN Security+ 4.0 SQL Injection

GEN Security+ version 4.0 suffers from a remote SQL injection vulnerability.

Geeklog 2.1.0b1 Database Disclosure

Geeklog version 2.1.0b1 suffers from a database disclosure vulnerability.

Forum Fire Soft Board 0.3.0 Cross Site Scripting

Forum Fire Soft Board version 0.3.0 suffers from a cross site scripting vulnerability.

Forma LMS 1.4 Database Disclosure

Forma LMS version 1.4 suffers from a database disclosure vulnerability.

Foodiee CMS 1.0.1 Insecure Direct Object Reference

Foodiee CMS version 1.0.1 suffers from an insecure direct object reference vulnerability.

Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints Ahead

Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaign

CVE-2023-41098: fix: [security] reflected xss on dashboard edit · MISP/MISP@09fb0cb

An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.