CVE-2022-39339 - How Plaintext OIDC Credential Leaks Put Nextcloud Accounts at Risk
user_oidc is a widely used OpenID Connect (OIDC) user backend for Nextcloud, enabling seamless SSO (Single Sign-On) integration with identity providers. On November
CVE-2022-45152 - Blind SSRF in Moodle’s LTI Provider – Exploit Details, Impact, and Mitigation
A significant security vulnerability (CVE-2022-45152) was discovered in Moodle, the widely used open-source learning management system. This bug is a Blind Server-
CVE-2022-41705 - Remote Code Execution in Badaso v2.6.3 Explained (How Attackers Exploit File Uploads)
If you use Badaso—the Laravel-based admin panel—especially version 2.6.3 or earlier, you need to know about CVE-2022-41705. This
CVE-2022-44860 - Critical SQL Injection in Automotive Shop Management System v1. – In-Depth Analysis and Exploitation
If you run or manage an automotive shop using the Automotive Shop Management System v1., you need to pay close attention to a serious security
CVE-2022-0698 - How an Unauthenticated XSS in Microweber 1.3.1 Allows Account Takeover
Microweber, an open-source drag-and-drop website builder, is known for its flexibility and ease of use. But, like all software, it’s not
Episode
00:00:00
00:00:00