1Panel Arbitrary File Download vulnerability

### Summary Any file downloading vulnerability exists in 1Panel backend. ### Details Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. ...

Continue Reading
1Panel Arbitrary File Download vulnerability

### Summary Any file downloading vulnerability exists in 1Panel backend. ### Details Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. ...

Continue Reading
1Panel arbitrary file write vulnerability

# Summary An arbitrary file write vulnerability could lead to direct control of the server # Details ## Arbitrary file creation In the api/v1/file.go file, there is a function called SaveContentthat,I ...

Continue Reading
WordPress WP Project Manager 2.6.4 Privilege Escalation

Post ContentRead More ...

Continue Reading
Request-Baskets v1.2.1 – Server-side request forgery (SSRF)

Post ContentRead More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 31, 2023 to August 6, 2023)

Last week, there were 29 vulnerabilities disclosed in 24 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 18 Vulnerab ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Focus on DroxiDat/SystemBC

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/07/28105711/abstract_dangerous_box-990x400.jpg) Recently we pushed a report to our customers about an interesting and common ...

Continue Reading
Missing brute force protection on OAuth2 API controller

## Description ### Impact Missing protection allows an attacker to brute force the client secrets of configured OAuth2 clients. ### Patches It is recommended that the Nextcloud Server is upgraded to 2 ...

Continue Reading

Back to Main

Subscribe for the latest news: