XWiki Platform’s tags on non-viewable pages can be revealed to users

### Impact Tags from pages not viewable to the current user are leaked by the tags API. This information can also be exploited to infer the document reference of non-viewable pages. ### Patches This v ...

Continue Reading
XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email

### Impact Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `/xwiki/bin/view/Main/?view ...

Continue Reading
When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

### Impact If you used the [apiPrefilter](https://remult.dev/docs/ref_entity.html#apiprefilter) option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unaut ...

Continue Reading
When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

### Impact If you used the [apiPrefilter](https://remult.dev/docs/ref_entity.html#apiprefilter) option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unaut ...

Continue Reading
Alert! Hackers Exploiting Critical Vulnerability in VMware’s Aria Operations Networks

[![Vulnerability in VMware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() VMware has flagged that a recently patched critical c ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

OWASP Top 10 API Security Risks: The 2023 Edition Is Finally Here

We review the final changes in the 2023 update to the OWASP Top 10 API Security Risks to help you on your journey to secure your APIs.Read More ...

Continue Reading
Cyber Asset Attack Surface Management 101

## Understanding CAASM ![Cyber Asset Attack Surface Management 101](https://blog.rapid7.com/content/images/2023/06/GettyImages-1216713090.jpg) _This article was written by Ethan Smart, Co-Founder and ...

Continue Reading
New Report Exposes Operation Triangulation’s Spyware Implant Targeting iOS Devices

[![Spyware Implant Targeting iOS Devices](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() More details have emerged about the spy ...

Continue Reading

Back to Main

Subscribe for the latest news: