Strapi mishandles hidden attributes within admin API responses

Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.Read More ...

Continue Reading
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

### Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
JVN#78862034: BookStack vulnerable to cross-site scripting

BookStack contains a cross-site scripting vulnerability (CWE-79). ## Impact An arbitrary script may be executed on the web browser of the user who is accessing the site using the API of the product. ...

Continue Reading
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

### Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
matrix-js-sdk subject to impersonated messages due to permissive key forwarding

## Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
[SECURITY] Fedora 35 Update: libofx-0.10.7-2.fc35

This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See https://www.ofx.net/ofx/default.as ...

Continue Reading
matrix-js-sdk subject to impersonated messages due to permissive key forwarding

## Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
Fast Company hacked to send obscene and racist messages

Yesterday, Apple News [announced]() it had disabled the channel of [Fast Company](), a US-based business magazine, after surprised Twitter users reported it was tweeting offensive comments. > An in ...

Continue Reading

Back to Main

Subscribe for the latest news: