Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[electron-markdownify] Markdownify has Files or Directories Accessible to External Parties

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/05/2022

Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at…

[fastest-json-copy] fastest-json-copy vulnerable to Prototype Pollution

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/08/2022

fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the __proto__ property to be edited.
Refe…

[deep-parse-json] deep-parse-json vulnerable to Prototype Pollution

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/08/2022

deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the __proto__ property to be edited.
Refere…

[deep-object-diff] deep-object-diff vulnerable to Prototype Pollution

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/17/2022

deep-object-diff before version 1.1.6 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited. Thi…

[org.apache.uima:uimaj-core] Apache UIMA Path Traversal vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 11/04/202211/04/2022

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apac…

[opencart/opencart] OpenCart allows users on admin page to obtain database information or read server files through SQL injection

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/05/2022

OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-37823
https://medium.com/@nowczj/sql-injection-exists-in-the-background-of-…

[org.kairosdb:kairosdb] Reflected Cross site scripting (XSS) in kairosdb

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/202211/04/2022

KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a ‘”sampling”:{“value”:”

[@keystone-6/core] @keystone-6/core’s NODE_ENV defaults to development with esbuild

  • Posted inCRITICAL
  • Posted byGitHub
  • 11/04/202211/05/2022

Impact
@keystone-6/core@3.0.0 || 3.0.1 users that use NODE_ENV in their own code (not dependencies) to trigger security-sensitive functionality in a production build are vulnerable to NODE_ENV being inlined to “development” for user code.
If your depen…

[in2code/femanager] TYPO3 Extension femanager vulnerable to Broken Access Control

  • Posted inMODERATE
  • Posted byGitHub
  • 11/04/2022

The TYPO3 Extension femanager prior to versions 5.5.2, 6.3.3, and 7.0.1 is vulnerable to broken access control. The usergroup.inList validation can be bypassed resulting in new frontend users created by the extension may be members of groups that are r…

[tribalsystems/zenario] Tribal Systems Zenario CMS vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 11/03/202211/04/2022

A vulnerability has been found in Tribal Systems Zenario CMS prior to version 8.5.51340. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripti…

Posts navigation

Previous Posts 1 … 16 17 18 19 20 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close