[webapps] GLPI 4.0.2 – Unauthenticated Local File Inclusion on Manageentities plugin
GLPI 4.0.2 – Unauthenticated Local File Inclusion on Manageentities plugin
GLPI 4.0.2 – Unauthenticated Local File Inclusion on Manageentities plugin
Paid Memberships Pro v2.9.8 (WordPress Plugin) – Unauthenticated SQL Injection
Metform Elementor Contact Form Builder v3.1.2 – Unauthenticated Stored Cross-Site Scripting (XSS)
Roxy WI v6.1.1.0 – Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
Categories: News Tags: Lock and Code Tags: Anna Pobletts Tags: ChatGPT Tags: World Backup Day Tags: GitHub Tags: accidental breach Tags: DDoS service Tags: Instagram scammer Tags: top cyber threats of 2023 Tags: 3CX Tags: BingBang Tags: Apple Tags: EE phing Tags: phishing Tags: ransomware The most interesting security related news from the week of March 27 to April 2. |
The post A week in security (March 27 – April 2) appeared first on Malwarebytes Labs.
HotKey Clipboard 2.1.0.6 – Privilege Escalation Unquoted Service Path
Roxy WI v6.1.0.0 – Unauthenticated Remote Code Execution (RCE)
Nacos 2.0.3 – Access Control vulnerability
GLPI Activity v3.1.0 – Authenticated Local File Inclusion on Activity plugin
Windows 11 10.0.22000 – Backup service Privilege Escalation