Apple Signs Shlayer, Legitimizes Malware

Apple Signs Shlayer, Legitimizes Malware
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2020-23831PUBLISHED: 2020-09-01

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an unauthenticated victim clicks on a malicious URL and enters credentials.

CVE-2020-23835PUBLISHED: 2020-09-01

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

CVE-2020-23836PUBLISHED: 2020-09-01

A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.

CVE-2020-23839PUBLISHED: 2020-09-01

A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login...

CVE-2020-6135PUBLISHED: 2020-09-01

An exploitable SQL injection vulnerability exists in the Validator.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request ..

Support the originator by clicking the read the rest link below.