Tag
#php
GEN Security+ version 4.0 suffers from a cross site scripting vulnerability.
Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.
GraceHRM version 1.0.3 suffers from a directory traversal vulnerability.
User Registration and Login and User Management System version 3.0 suffers from a persistent cross site scripting vulnerability.
User Registration and Login and User Management System version 3.0 suffers from a remote SQL injection vulnerability.
Uvdesk version 1.1.4 suffers from a persistent cross site scripting vulnerability.
FAST TECH CMS version 1.0 suffers from a cross site request forgery vulnerability.
doorGets CMS version 12 suffers from a remote shell upload vulnerability.
Lazarus Group appears to be changing its tactics, increasingly relying on open-source tools and frameworks in the initial access phase of their attacks, as opposed to strictly employing them in the post-compromise phase.
This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.