PrestaShop file deletion via CustomerMessage

### Impact It is possible to delete files from the server via the CustomerMessage API ### Patches 8.1.1 ### Found by Kto94 (via Yeswehack) ### Workarounds none ### References noneRead More ...

Continue Reading
(RHSA-2023:4590) Moderate: Red Hat Ansible Automation Platform 2.3 Product Security and Bug Fix Update

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is appli ...

Continue Reading
Continuous Security Validation with Penetration Testing as a Service (PTaaS)

[![Penetration Testing as a Service](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() _Validate security continuously across your ...

Continue Reading
Xurlfind3R – A CLI Utility To Find Domain’S Known URLs From Curated Passive Online Sources

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivXVw6TPPGXu8D8a8ag8ORzKUKxWn5kozCSoQV_ItikHjQfVDTwckyb5e95g6a4ly6y3nnawWoYTIYpVzoLNT7ygKPRvoLTQDDVyIFBMnUfyU0q5tHoSccR7ILL9-O7GlTxTT4Vw ...

Continue Reading
CVE-2023-37862

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-co ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-4243

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows au ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-38752

Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute information of the poster ...

Continue Reading
CVE-2023-38751

Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the info ...

Continue Reading

Back to Main

Subscribe for the latest news: