Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-1172PUBLISHED: 2023-03-17
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...
CVE-2023-1469PUBLISHED: 2023-03-17
The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
CVE-2023-1466PUBLISHED: 2023-03-17
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(...
CVE-2023-1467PUBLISHED: 2023-03-17
A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the input C%3A%2Ffoo.txt le...
CVE-2023-1468PUBLISHED: 2023-03-17
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipula...
User Rank: Apprentice
1/28/2016 | 3:46:25 PM
"Any decision regarding methodology, vendor, product, or service that doesn't demonstrably increase efficiency and efficacy is a bad decision"
Rings true and echoes the assertions of the NoIT and NoDev principles:
"Eliminate IT systems that demand the attention of humans" and "Only engage in development projects that unambiguously and unequivocally generate revenue for the business or enhance customer experience"
Decisions pertaining to Cyber Security must be held to the same principles. While it may be a stretch to say that poor Cyber Security spending can kill a business; burdensome administration, proliferation of manual processes and the introduction of disjointed IT systems can have a greater negative effect on the bottom line than the secrutiy threats they purport to mitigate.
There are emerging technologies that can make a great impact on increasing the ROI of Cyber Security and CISOs should seize the opportunity to leverage innovation to reduce costs and streamline the administrative processes they own.
I look forward to your future article on this subject.