In Moodle versions prior to 4.1.14, from 4.2.0 before 4.2.11, from 4.3.0 before 4.3.8, and from 4.4.0 before 4.4.4 a medium severity vulnerability CVE-2024-48896 was detected. This vulnerability allows users with “send message” rights to see names of other users through an error message, even if they shouldn’t have access. The displayed name follows the site’s configured full-name format. To fix this issue, users need to update to versions 4.1.14, 4.2.11, 4.3.8, or 4.4.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-48896.
Read more EducationalIn LibreNMS versions before 24.10.0 a medium severity vulnerability CVE-2024-52526 was detected. This vulnerability allows authenticated users to inject arbitrary JavaScript through the “descr” parameter in the “Services” tab of the Device page. This could result in the execution of malicious code within the context of other users’ sessions, potentially compromising their accounts and enabling unauthorized actions. To address this issue, update to LibreNMS version 24.10.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52526.
Read more MonitoringIn LibreNMS versions before 24.10.0 a medium severity vulnerability CVE-2024-51497 was found. It allows logged-in users to add harmful code through the “Custom OID” tab. OID (Object Identifier) is a unique number used to identify specific items or settings in network devices. When creating a new OID, this issue could let attackers run malicious actions on other users’ accounts. To fix this, update to LibreNMS version 24.10.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-51497.
Read more MonitoringIn LibreNMS versions before 24.10.0 a medium severity vulnerability CVE-2024-51496 was found in the “metric” parameter of the “/wireless” and “/health” pages. This issue allows attackers to inject harmful code that runs when a user visits these pages. This could compromise the user’s session and allow unauthorized actions. To fix this, update to LibreNMS version 24.10.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-51496.
Read more MonitoringIn LibreNMS versions before 24.10.0 a medium severity vulnerability CVE-2024-51495 was found in the Device Overview page. This issue allows authenticated users to inject harmful code through the “overwrite_ip” parameter when editing a device. When the page is visited, the malicious code is executed, potentially compromising the accounts of other users. To fix this, update to LibreNMS version 24.10.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-51495.
Read more MonitoringIn Apache Airflow versions prior to 2.10.3 a high severity vulnerability CVE-2024-45784 was detected. This vulnerability could expose sensitive configuration variables in task logs, potentially allowing unauthorized access and exploitation. Masking secrets in logs is recommended to prevent exposure. To fix this problem, users should upgrade to version 2.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45784.
Read more Data AnalyticsIn WordPress in all versions up to and including 16.6 a critical severity vulnerability CVE-2024-11150 was detected. This vulnerability allows attackers to delete arbitrary files on the server, potentially enabling remote code execution. To fix this problem, users should upgrade to version 16.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11150.
Read more CMSIn WooCommerce in all versions up to and including 2.2.9 a medium severity vulnerability CVE-2024-10854 was detected. This vulnerability allows attackers with low-level access to import and modify plugin settings, potentially compromising data. To fix this problem, users should upgrade to the latest version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10854.
Read more E-commerceIn Harbor versions prior to 2.5.2 a high severity vulnerability CVE-2022-31670 was detected. This vulnerability allows an attacker to modify tag retention policies in projects they don’t have access to by sending a request with a policy ID from another project, due to Harbor’s failure to validate user permissions. To fix this issue, users need to update to version 2.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31670.
Read more Developer Tools