Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /.. ...
Continue ReadingJune 02, 2022
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL.Read More ...
Continue ReadingJune 02, 2022
An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application a ...
Continue ReadingJune 02, 2022
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method write ...
Continue ReadingJune 02, 2022
There is no question that the level of threats facing todays businesses continues to change on a daily basis. So what are the trends that CISOs need to be on the lookout for? For this episode of the ...
Continue ReadingJune 02, 2022
When files are uploaded into dotCMS via the content API, but before they become content, dotCMS writes the file down in a temporary directory. In the case of this vulnerability, dotCMS does not saniti ...
Continue ReadingJune 02, 2022
Discord a public chat application designed for gamers has grown popular among crypto owners all over the world. Attackers are targeting the Discord servers of several popular nonfungible token (NFT) p ...
Continue ReadingJune 02, 2022
Back to Main