Company
Date Published
Author
Detectify
Word count
101
Language
-
Hacker News points
None

Summary

A recent update has introduced a new set of vulnerabilities affecting various platforms, including Sitecore, HashiCorp Consul, and WordPress. The vulnerabilities encompass a range of issues such as information exposure in .NET affecting Sitecore and Episerver, exposure of MySQL and PostgreSQL history files, and several WordPress-specific vulnerabilities like SQL injection, object injection, authentication bypass, cross-site scripting (XSS), and server-side request forgery (SSRF). Specific vulnerabilities include phpMyFAQ XSS, WordPress simple-login-log SQL injection, and authenticated open redirects in BuddyPress, among others. Users are advised to conduct scans to determine if they are susceptible to these vulnerabilities.