Get a Pentest and security assessment of your IT network.

Cyber Security

Critical Flaws Reported in Etherpad a Popular Google Docs Alternative

Researchers have disclosed new security vulnerabilities in Etherpad text editor. The flaws were discovered and reported on June 4 by researchers from SonarSource. One vulnerability resides in the chat feature offered by Etherpad, with the “userId” property of a chat message rendered on the front-end without properly escaping special characters. The other flaw relates to how Etherpad manages plugins, where the name of the package to be installed via the “npm install” command is not adequately sanitized, leading to a scenario that could allow an attacker to “specify a malicious package from the NPM repository”

Source: https://thehackernews.com/2021/07/critical-flaws-reported-in-etherpad.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security