Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-31884PUBLISHED: 2022-06-28Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
CVE-2022-31887PUBLISHED: 2022-06-28Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
CVE-2020-19896PUBLISHED: 2022-06-28File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
CVE-2020-19897PUBLISHED: 2022-06-28A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
CVE-2021-41559PUBLISHED: 2022-06-28Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
User Rank: Apprentice
1/23/2017 | 9:51:37 AM
I saw several companies where IT Security people found new apps running on the cloud by mistake. I saw users going alone to the cloud because when they requested new power to IT, received as answer a kind of 30... 45 days to deliver, I saw users going alone to the cloud because they want to start a project very light and have the capacity to grow fast if project has success but IT simply can't do it.
Cloud is not for everything, not for everyone (at this moment, because market is changing so fast) but if our IT can't support market changes in terms of usability, flexibility and cost, there is no other way to go instead to the cloud, in a secure or insecure way.