Company
Date Published
Author
Detectify
Word count
688
Language
-
Hacker News points
None

Summary

Detectify's Crowdsource ethical hacker community has identified several security vulnerabilities across various platforms, which have been promptly integrated into the Detectify scanner for user protection. Notable vulnerabilities include remote code execution (RCE) issues in VMware vCenter and Apache Tapestry, file disclosure threats in Express Handlebars, and SQL injection vulnerabilities in OpenProject, ISPConfig, and SonicWall SMA 100. Additionally, cross-site scripting (XSS) flaws were found in Cisco ASA/FTD, Grafana, OX Appsuite, and EPrints, while WooCommerce and ElasticSearch faced SQL injection and memory disclosure threats, respectively. A path traversal vulnerability in Eclipse Jetty and a command injection issue in Hasura GraphQL Engine further underscore the diverse nature of these reported threats, highlighting the ongoing need for robust cybersecurity measures.