Skip to content

Underground News

Header Image
Category

severity

65 Posts

Featured

Posted byGitHub
[@ckeditor/ckeditor5-markdown-gfm] CKEditor5 Cross-site scripting caused by the editor instance destroying process
Posted byGitHub
[drupal/core] Drupal core arbitrary PHP code execution
Posted byGitHub
[streamlit] Streamlit directory traversal vulnerability
Posted byGitHub
[org.postgresql:postgresql] PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names

[node-fetch] node-fetch Inefficient Regular Expression Complexity

  • Posted inseverity
  • Posted byGitHub
  • 08/02/202208/05/2022

node-fetch is a light-weight module that brings window.fetch to node.js.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the isOriginPotentiallyTrustworthy() function in referrer.js, when processing a…

[github.com/runatlantis/atlantis/server/controllers/events] Atlantis Events prior to 0.19.7 vulnerable to Timing Attack

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/09/2022

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow…

[prestashop/prestashop] PrestaShop eval injection possible if shop vulnerable to SQL injection

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/04/2022

Impact
Eval injection possible if the shop is vulnerable to an SQL injection.
Patches
The problem is fixed in version 1.7.8.7
Workarounds
Delete the MySQL Smarty cache feature by removing these lines in the file config/smarty.config.inc.php lines 43-46…

[co.fs2:fs2-io] fs2-io skips mTLS client verification

  • Posted inseverity
  • Posted byGitHub
  • 07/30/202208/04/2022

Impact
When establishing a server-mode TLSSocket using fs2-io on Node.js, the parameter requestCert = true is ignored, peer certificate verification is skipped, and the connection proceeds.
The vulnerability is limited to:

fs2-io running on Node.js. T…

[feehi/cms] Feehi CMS Cross-site Scripting

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
References

https://nvd.nist.gov/vuln/…

[org.apache.calcite.avatica:avatica-core] Apache Calcite Avatica JDBC driver arbitrary code execution

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via httpclient_impl connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which ca…

[mongoose] Prototype pollution Schema.path in automattic/mongoose

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/04/2022

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.\n\nAffected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the sch…

[reqmon] WMAgent arbitrary code execution via a crafted dbs-client package

  • Posted inseverity
  • Posted byGitHub
  • 07/29/202208/06/2022

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34558
https…

[feehi/cms] Feehi CMS arbitrary code execution via crafted PHP file

  • Posted inseverity
  • Posted byGitHub
  • 07/28/202208/06/2022

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34971
https://github.com/liufee/cms…

[shopware/shopware] Shopware vulnerable to persistent cross site scripting (XSS) in customer module

  • Posted inseverity
  • Posted byGitHub
  • 07/28/202208/04/2022

Impact
Persistent XSS in customer module
Patches
We recommend updating to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview.
For older versions you can use the Security Plu…

Posts navigation

Previous Posts 1 2 3 4 5 … 7 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close