Get a Pentest and security assessment of your IT network.

News

Vulnerability Spotlight: TALOS-2018-0560 – ERPNext SQL Injection Vulnerabilities

Vulnerabilities discovered by Yuri Kramarz from Cisco Security Advisor Team. Talos disclosing multiple SQL injection vulnerabilities in Frappe ERPNext Version 10.1.6 application. These vulnerabilities enable an attacker to bypass authentication and get unauthenticated access to sensitive data. An attacker can use a normal web browser to trigger these vulnerabilities no special tools are required. The vulnerabilities were assigned to the CVE IDs CVE-2018-3882 – CVE-2019-3885. The following Snort rules will detect exploitation attempts.”]

Source: https://blog.talosintelligence.com/2018/09/vulnerability-spotlight-talos-2018-0560.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months