Wordfence Intelligence Weekly WordPress Vulnerability Report (January 1, 2023 to January 7, 2023)

Wordfence just launched its bug bounty program. For the first 6 months, all awarded bounties receive a 10% bonus. View the announcement to learn more now! Last week, there were 85 vulnerabilities disc ...

Continue Reading
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

Summary The OrderAndPaginate function is used to order and paginate data. It is defined as follows: ```go func OrderAndPaginate(c gin.Context) func(db gorm.DB) gorm.DB { return func(db gorm.DB) *g ...

Continue Reading
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

Summary The OrderAndPaginate function is used to order and paginate data. It is defined as follows: ```go func OrderAndPaginate(c gin.Context) func(db gorm.DB) gorm.DB { return func(db gorm.DB) *g ...

Continue Reading
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)

Summary The Home > Preference page exposes a small list of nginx settings such as Nginx Access Log Path and Nginx Error Log Path. However, the API also exposes test_config_cmd, reload_cmd and r ...

Continue Reading
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)

Summary The Home > Preference page exposes a small list of nginx settings such as Nginx Access Log Path and Nginx Error Log Path. However, the API also exposes test_config_cmd, reload_cmd and r ...

Continue Reading
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)

Summary Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. Details The Home > Preference page exp ...

Continue Reading
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)

Summary Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. Details The Home > Preference page exp ...

Continue Reading
tomcat security update

[1:9.0.62-27.2] - Open Redirect vulnerability in FORM authentication (CVE-2023-41080) - FileUpload: DoS due to accumulation of temporary files on Windows (CVE-2023-42794) - improper cleaning of recycl ...

Continue Reading

Back to Main

Subscribe for the latest news: